Anders Schack-Mulligen
|
8a20395857
|
Merge pull request #5940 from pwntester/main
Remove XSS sink for Java
|
2021-06-02 12:30:20 +02:00 |
|
Anders Schack-Mulligen
|
c0e562de21
|
Merge pull request #5979 from hvitved/java/shared-external-summaries
Java: Move some CSV flow summary code into shared library
|
2021-06-02 12:28:45 +02:00 |
|
Tony Torralba
|
d476459727
|
Use InlineExpectationsTest
|
2021-06-02 12:15:26 +02:00 |
|
Tony Torralba
|
b30c92e69e
|
Refactored into MvelInjection.qll using CSV models
|
2021-06-02 11:33:01 +02:00 |
|
Alvaro Muñoz
|
a3a215afea
|
HTTP -> Http
|
2021-06-02 11:12:39 +02:00 |
|
Anders Schack-Mulligen
|
5e96e28792
|
Java: Add missing metadata.
|
2021-06-02 10:24:46 +02:00 |
|
Tony Torralba
|
59e6e1ffac
|
Moved from experimental
|
2021-06-02 09:58:30 +02:00 |
|
Tamás Vajk
|
348fab82fd
|
Merge pull request #5970 from tamasvajk/feature/csv-coverage-impr
Improve error reporting in CI check for CSV coverage report comparison
|
2021-06-02 09:03:35 +02:00 |
|
Alvaro Muñoz
|
9aba92397d
|
lift XssSink check to InformationLeakSink
|
2021-06-01 17:16:41 +02:00 |
|
Jonas Jensen
|
7282ad90d0
|
Merge pull request #5854 from dbartol/dbartol/smart-pointers/side-effects
C++: Generate side effect instructions for smart pointer indirections
|
2021-06-01 16:57:05 +02:00 |
|
Dave Bartolomeo
|
da14647e5a
|
Merge pull request #5522 from github/rdmarsh2/cpp/ssa-reuse
C++: reuse unaliased SSA results when computing aliased SSA
|
2021-06-01 10:17:54 -04:00 |
|
Anders Schack-Mulligen
|
650c4f19d2
|
Java: More qldoc.
|
2021-06-01 16:09:17 +02:00 |
|
Alvaro Muñoz
|
970b4e7d6a
|
update java library coverage documentation
|
2021-06-01 14:54:31 +02:00 |
|
Anders Schack-Mulligen
|
922b421a45
|
Java: Add change note.
|
2021-06-01 14:33:52 +02:00 |
|
Anders Schack-Mulligen
|
1c081eeaed
|
Java: Update coverage.
|
2021-06-01 14:00:05 +02:00 |
|
Alvaro Muñoz
|
0fb692400c
|
fix failing test
|
2021-06-01 13:57:13 +02:00 |
|
Tom Hvitved
|
ecf7f24cde
|
C#: Sync latest FlowSummaryImpl.qll changes
|
2021-06-01 13:22:14 +02:00 |
|
Tom Hvitved
|
14f9a5c280
|
Java: Move some CSV flow summary code into shared library
|
2021-06-01 13:22:14 +02:00 |
|
Henning Makholm
|
534e771309
|
Merge pull request #5934 from github/hmakholm/pr/monotonic-agg
QL language reference: add monotonic aggregate example
|
2021-06-01 13:10:50 +02:00 |
|
Tamás Vajk
|
e7a349be2d
|
Merge pull request #5978 from tamasvajk/fix/change-note-workflow
Fix change note workflow to handle paginated results
|
2021-06-01 12:50:32 +02:00 |
|
Anders Schack-Mulligen
|
fc913e744e
|
Java: Minor model fix.
|
2021-06-01 11:47:52 +02:00 |
|
Anders Schack-Mulligen
|
dbe352f3ff
|
Java: Remove deprecated tests.
|
2021-06-01 11:47:52 +02:00 |
|
Anders Schack-Mulligen
|
901996f9fd
|
Java: Add collection flow test.
|
2021-06-01 11:47:52 +02:00 |
|
Anders Schack-Mulligen
|
43d1b0ab27
|
Java: Update qltests.
|
2021-06-01 11:47:52 +02:00 |
|
Anders Schack-Mulligen
|
a40880af70
|
Java: Add read-as-taint and config-dependent store-as-taint.
|
2021-06-01 11:47:52 +02:00 |
|
Anders Schack-Mulligen
|
2f087e17cb
|
Java: Allow <> in types for now.
|
2021-06-01 11:47:52 +02:00 |
|
Anders Schack-Mulligen
|
3f538e7fac
|
Java: Update some models.
|
2021-06-01 11:47:52 +02:00 |
|
Anders Schack-Mulligen
|
9e313d0cf6
|
Java: Remove container taint steps.
|
2021-06-01 11:47:52 +02:00 |
|
Anders Schack-Mulligen
|
3b6cef4f74
|
Java: Add container flow models.
|
2021-06-01 11:47:52 +02:00 |
|
Anders Schack-Mulligen
|
ffd52bb673
|
Java: Fix bug in matching generic signatures.
|
2021-06-01 11:47:52 +02:00 |
|
Anders Schack-Mulligen
|
1001dd84e6
|
Java: Switch array steps and one containerstep.
|
2021-06-01 11:47:52 +02:00 |
|
Anders Schack-Mulligen
|
ce509eb7e1
|
Merge pull request #5927 from aschackmull/dataflow/flowthrough-dispatch-perf
Dataflow: Improve performance in flow-through pruning
|
2021-06-01 11:46:22 +02:00 |
|
Anders Schack-Mulligen
|
a4661e1aca
|
Merge pull request #5704 from edvraa/regexj
Java: Regex injection
|
2021-06-01 11:45:59 +02:00 |
|
Artem Smotrakov
|
8dc1451d42
|
Better recommendation in UnsafeDeserializationRmi.qhelp
Co-authored-by: Chris Smowton <smowton@github.com>
|
2021-06-01 12:16:09 +03:00 |
|
Erik Krogh Kristensen
|
0b225419a3
|
Merge pull request #5977 from security-prince/patch-1
Adding reference link for csurf
|
2021-06-01 11:07:36 +02:00 |
|
Tom Hvitved
|
5771b0420f
|
Merge pull request #5936 from hvitved/csharp/cfg/perf-tweaks
C#: Various CFG related performance tweaks
|
2021-06-01 11:06:01 +02:00 |
|
Anders Schack-Mulligen
|
5d21c64247
|
Dataflow: qldoc fix.
|
2021-06-01 10:49:47 +02:00 |
|
Tamas Vajk
|
bc02f28ddd
|
Fix change note workflow to handle paginated results
|
2021-06-01 10:44:44 +02:00 |
|
Jonas Jensen
|
2261085cfe
|
Merge pull request #5973 from MathiasVP/more-uncontrolled-arith-improvements
C++: More `cpp/uncontrolled-arithmetic` improvements
|
2021-06-01 10:44:29 +02:00 |
|
Anders Schack-Mulligen
|
4f9a6c151b
|
Dataflow: Code review fixes.
|
2021-06-01 10:29:17 +02:00 |
|
Mathias Vorreiter Pedersen
|
8765c33847
|
C++: Also check the number of parameters to keep the tests happy.
|
2021-06-01 10:17:57 +02:00 |
|
Ishaq Mohammed
|
96150a455d
|
Update javascript/ql/src/Security/CWE-352/MissingCsrfMiddleware.qhelp
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2021-06-01 13:47:43 +05:30 |
|
Ishaq Mohammed
|
975355de4a
|
Adding reference link for csurf
|
2021-06-01 13:41:25 +05:30 |
|
Mathias Vorreiter Pedersen
|
615c805b2c
|
C++: Only use std::rand as a source of randomness.
|
2021-06-01 09:28:06 +02:00 |
|
Henning Makholm
|
70b9739d2d
|
QL language reference: add monotonic aggregate example
It's easier to understand what's going on if we start with a
(contrived) example that _doesn't_ involve recursion.
|
2021-05-31 21:23:08 +02:00 |
|
Mathias Vorreiter Pedersen
|
41c93d92d7
|
C++: Remove FPs from right shifts and explicitly bounded random functions.
|
2021-05-31 15:40:02 +02:00 |
|
Mathias Vorreiter Pedersen
|
10755ece88
|
C++: Add testcase with bounded randomness source.
|
2021-05-31 15:33:39 +02:00 |
|
Anders Schack-Mulligen
|
683f853fa5
|
Dataflow: Fix another bad join order.
|
2021-05-31 15:14:13 +02:00 |
|
Erik Krogh Kristensen
|
85bd8f1020
|
add change-note for TypeScript 4.3
|
2021-05-31 13:08:52 +02:00 |
|
Erik Krogh Kristensen
|
e6b1c61e81
|
add tests for TypeScript 4.3
|
2021-05-31 13:08:43 +02:00 |
|