github-actions[bot]
|
6b194bc55f
|
Release preparation for version 2.8.3
|
2022-03-10 19:43:58 +00:00 |
|
Alex Ford
|
305a51754c
|
Run python config/sync-files.py
|
2022-03-10 18:34:16 +00:00 |
|
Alex Ford
|
2b25765156
|
Format QL
|
2022-03-10 17:55:42 +00:00 |
|
Alex Ford
|
0f3cf47ca9
|
Ruby/JS/Py: Add "random" to the notSensitiveRegexp() heuristic
|
2022-03-10 17:38:52 +00:00 |
|
Erik Krogh Kristensen
|
41778328c2
|
Update javascript/ql/lib/semmle/javascript/dataflow/Sources.qll
Co-authored-by: Stephan Brandauer <kaeluka@github.com>
|
2022-03-10 14:16:28 +01:00 |
|
Erik Krogh Kristensen
|
c2743177af
|
JS: delete the TrackedNodes.qll, it had no public interface left
|
2022-03-10 11:34:17 +01:00 |
|
Erik Krogh Kristensen
|
e6b0552114
|
JS: delete leftover comment
|
2022-03-10 10:25:02 +01:00 |
|
Erik Krogh Kristensen
|
9c4fcf4c6d
|
fix typo in change-note
Co-authored-by: Stephan Brandauer <kaeluka@github.com>
|
2022-03-09 18:28:13 +01:00 |
|
Erik Krogh Kristensen
|
6a28ddd9ec
|
JS: un-deprecate deleted deprecated class that defined taint-steps
|
2022-03-09 18:28:12 +01:00 |
|
Erik Krogh Kristensen
|
59db0e7a0f
|
JS: delete unused predicate
|
2022-03-09 18:28:12 +01:00 |
|
Erik Krogh Kristensen
|
c48a5a1294
|
JS: update tests to not use deleted deprecations
|
2022-03-09 18:28:12 +01:00 |
|
Erik Krogh Kristensen
|
5312e4a8b5
|
add change note that all old deprecations were deleted
|
2022-03-09 18:28:11 +01:00 |
|
Erik Krogh Kristensen
|
a86f0afb3c
|
delete all deprecations that are over 14 months old
|
2022-03-09 18:28:07 +01:00 |
|
Arthur Baars
|
747c7f6b5e
|
JS/Ruby: share implementation of IncompleteUrlSubstringSanitization query
|
2022-03-09 12:11:14 +01:00 |
|
Erik Krogh Kristensen
|
cebd24156c
|
support that the base is not a method-call in getAChainedMethodCall
|
2022-03-09 11:12:04 +01:00 |
|
Erik Krogh Kristensen
|
4734f1916e
|
Merge pull request #7598 from erik-krogh/fieldOnlyUsedInCharPred
QL: field only used in charPred
|
2022-03-08 11:25:57 +01:00 |
|
Arthur Baars
|
bb348116ab
|
JavaScript: update expected output
|
2022-03-07 16:10:08 +01:00 |
|
Arthur Baars
|
98f56f4d60
|
Js/Ruby: Share IncompleteHostnameRegExp.ql
|
2022-03-07 16:10:08 +01:00 |
|
Arthur Baars
|
9e8930c192
|
Ruby: IncompleteHostnameRegExp.ql
|
2022-03-07 16:10:08 +01:00 |
|
Arthur Baars
|
eeb9a1d270
|
JavaScript: fix typos in documentation
|
2022-03-07 16:09:13 +01:00 |
|
Tom Bolton
|
173f45f316
|
Merge pull request #8334 from github/tombolton/add-mapping-query
JS: Add query that maps queries to sink type
|
2022-03-07 10:35:37 +00:00 |
|
Tiferet Gazit
|
bbc712fdb3
|
Merge pull request #8297 from erik-krogh/atmPerf
JS: Fix ATM timeout on NodeJS
|
2022-03-04 10:41:35 -08:00 |
|
tombolton
|
2ffa6771ff
|
replace endpoint type name with encoding in mapping query
|
2022-03-04 11:00:31 +00:00 |
|
tombolton
|
bd9e845aea
|
update column names and remove encoding value
|
2022-03-03 15:59:10 +00:00 |
|
tombolton
|
f1f1526237
|
add query-sink mapping query
|
2022-03-03 15:20:06 +00:00 |
|
Erik Krogh Kristensen
|
62f2614f72
|
move hasDominatingWrite to the TypeTracking stage
|
2022-03-02 11:30:05 +01:00 |
|
Erik Krogh Kristensen
|
1db6a644a5
|
only block flow for dominated reads when the property name is known
|
2022-03-02 11:30:05 +01:00 |
|
Erik Krogh Kristensen
|
a9062cc047
|
merge hasDominatingWrite and hasDominatingAssignment
|
2022-03-02 11:30:05 +01:00 |
|
Asger Feldthaus
|
d808bdc028
|
JS: Sync ApiGraphModels.qll
|
2022-03-01 14:08:20 +01:00 |
|
Tamás Vajk
|
94cb5c2be4
|
Merge pull request #8296 from github/post-release-prep/codeql-cli-2.8.2
Post-release preparation for codeql-cli-2.8.2
|
2022-03-01 11:57:36 +01:00 |
|
Erik Krogh Kristensen
|
dfc74d728b
|
fix duplicate words in qldoc
|
2022-03-01 11:22:58 +01:00 |
|
Erik Krogh Kristensen
|
1b5c7392f0
|
restrict the size of the getASubexpressionWithinQuery predicate, and remove double-recursion
|
2022-03-01 11:18:42 +01:00 |
|
Erik Krogh Kristensen
|
bdd07de7ed
|
improve performance of getTestFile by finding possible test files first
|
2022-03-01 11:18:22 +01:00 |
|
github-actions[bot]
|
980f822983
|
Post-release preparation for codeql-cli-2.8.2
|
2022-03-01 09:24:30 +00:00 |
|
Erik Krogh Kristensen
|
4c58f9781b
|
add support for TypeScript 4.6
|
2022-03-01 09:56:21 +01:00 |
|
Erik Krogh Kristensen
|
2b7c819135
|
fix extension of change-note
|
2022-03-01 09:54:19 +01:00 |
|
Erik Krogh Kristensen
|
4fba5e4dfb
|
step through parentheses in barrier functions
|
2022-02-25 17:47:12 +01:00 |
|
Asger F
|
a8bfebaeb6
|
Merge pull request #8149 from asgerf/shared/use-shared-access-path-syntax
Shared: use shared access path syntax to parse arguments in CSV rows
|
2022-02-25 14:04:18 +01:00 |
|
Tom Bolton
|
8dfc0d25d1
|
Merge pull request #8232 from github/tombolton/use-updated-counting-query
Add new xss queries to result counting query
|
2022-02-24 16:38:53 +00:00 |
|
github-actions[bot]
|
20fe22c8c8
|
Release preparation for version 2.8.2
|
2022-02-24 14:57:08 +00:00 |
|
tombolton
|
d80ef6566d
|
add new xss queries to result counting query
|
2022-02-24 13:31:40 +00:00 |
|
Erik Krogh Kristensen
|
ad3399733b
|
recognize more module exports from the factory pattern
|
2022-02-23 21:29:45 +01:00 |
|
Erik Krogh Kristensen
|
e13b2df86f
|
Merge pull request #8185 from erik-krogh/amdImp
JS: recognize modules imported by AMD imports as library inputs
|
2022-02-23 20:21:45 +01:00 |
|
Asger Feldthaus
|
f1bfb31403
|
Shared: fix typo in a comment
|
2022-02-23 14:13:41 +01:00 |
|
Asger Feldthaus
|
abd4933d6c
|
Shared: move numeric parsing into AccessPathSyntax.qll
|
2022-02-23 14:13:37 +01:00 |
|
CodeQL CI
|
7d55771092
|
Merge pull request #8150 from asgerf/js/prep-sharing-api-graph-mad
Approved by erik-krogh
|
2022-02-23 11:59:31 +00:00 |
|
CodeQL CI
|
62ee8fce3a
|
Merge pull request #8186 from asgerf/js/request-forgery-docs-followup
Approved by esbena, hubwriter
|
2022-02-23 11:46:37 +00:00 |
|
Stephan Brandauer
|
a664e02d04
|
Merge pull request #8014 from kaeluka/js/functionality-from-untrusted-source
JS: Functionality from untrusted sources query (CWE-830)
|
2022-02-23 12:45:31 +01:00 |
|
Stephan Brandauer
|
1ed71e15f3
|
apply docreview feedback
|
2022-02-23 11:21:22 +01:00 |
|
Stephan Brandauer
|
517d6969e1
|
Merge pull request #8171 from kaeluka/js/update-atm-query-docs-for-nosql-sql-injection
update ATM NosqlInjection and SqlInjection query docs
|
2022-02-23 10:54:37 +01:00 |
|