Jami
|
5259a6ecfc
|
Merge pull request #13324 from jcogs33/jcogs33/shared-sink-kind-validation
Shared: share MaD kind validation across languages
|
2023-06-20 11:56:12 -04:00 |
|
Owen Mansel-Chan
|
d7c97f8759
|
Merge pull request #13455 from owen-mc/dataflow/add-flowCheckNodeSpecific
Dataflow: add language-specific hook for breaking up big step relation
|
2023-06-20 13:24:26 +01:00 |
|
Jeroen Ketema
|
9c774ac97f
|
Merge pull request #13426 from jketema/inline-3
Update inline flow tests to use parameterized module
|
2023-06-19 17:39:29 +02:00 |
|
Jean Helie
|
423336310c
|
Merge pull request #13480 from github/jhelie/clean-up-mad-kinds-use
Java: clean up mad kinds use
|
2023-06-19 16:21:20 +02:00 |
|
Tony Torralba
|
c62689022e
|
Merge pull request #13256 from atorralba/atorralba/java/stapler-models
Java: Model the Stapler framework
|
2023-06-19 15:27:19 +02:00 |
|
Tony Torralba
|
00fe8adc09
|
Fix name clash
|
2023-06-19 15:04:33 +02:00 |
|
Tony Torralba
|
5cb451b040
|
Merge pull request #13475 from atorralba/atorralba/many/zipslip-docs-update
C#/Go/Java/JS/Python/Ruby: Update the description and qhelp of the Zipslip query
|
2023-06-19 14:33:44 +02:00 |
|
Ian Lynagh
|
ec73f28d09
|
Merge pull request #13479 from igfoo/igfoo/ENUM_ENTRIES
Kotlin: Handle IrSyntheticBodyKind.ENUM_ENTRIES
|
2023-06-19 12:57:10 +01:00 |
|
Ian Lynagh
|
ca5bc6f224
|
Java: Add up/downgrade scripts
|
2023-06-19 10:36:29 +01:00 |
|
Ian Lynagh
|
1f538cced3
|
Kotlin: Handle IrSyntheticBodyKind.ENUM_ENTRIES
Generated by Kotlin 1.9 for some of our tests.
|
2023-06-19 10:36:29 +01:00 |
|
Jeroen Ketema
|
bc42308bd3
|
Java: fix formatting
|
2023-06-19 10:31:49 +02:00 |
|
Jeroen Ketema
|
6a84e6cbfd
|
Add the merged PathGraph to all copies of the InlineFlowTest library
|
2023-06-19 10:28:10 +02:00 |
|
Tony Torralba
|
8f6d2ed2f9
|
Adjust ZipSlip query description according to review suggestions.
|
2023-06-19 10:27:41 +02:00 |
|
Tony Torralba
|
3c4d938cf1
|
Apply code review suggestions.
Co-authored-by: Asger F <asgerf@github.com>
|
2023-06-19 10:20:19 +02:00 |
|
Tony Torralba
|
433fc680ec
|
Apply suggestions from code review
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
|
2023-06-19 10:17:40 +02:00 |
|
Jean Helie
|
baf6b74945
|
use new sink mad kinds and simplify isKnownKind predicate
|
2023-06-16 13:58:23 +02:00 |
|
Jean Helie
|
daf2743143
|
only use neutral models of kind "sink"
|
2023-06-16 13:58:23 +02:00 |
|
Ian Lynagh
|
a8acf16088
|
Kotlin: Remove diags.ql from classes test
The diags consistency test already handles this for us.
|
2023-06-16 12:57:19 +01:00 |
|
Tony Torralba
|
c97868f774
|
Add change notes
|
2023-06-16 09:01:02 +02:00 |
|
Tony Torralba
|
3e96fe60c5
|
Go/Java/JS/Python/Ruby: Update the description and qhelp of the ZipSlip query
All filesystem operations, not just writes, with paths built from untrusted archive entry names are dangerous
|
2023-06-16 08:52:44 +02:00 |
|
Tony Torralba
|
1b39faaded
|
QLDoc correction
|
2023-06-15 16:20:39 +02:00 |
|
Jeroen Ketema
|
742eb8dd12
|
Java: Rewrite InlineFlowTest as a parameterized module
|
2023-06-15 10:52:10 +02:00 |
|
Owen Mansel-Chan
|
3ff6d033d3
|
Rename to neverSkipInPathGraph
|
2023-06-14 15:29:54 +01:00 |
|
Tony Torralba
|
37a62d3021
|
Merge pull request #13227 from atorralba/atorralba/java/jenkins-generated-models
Java: Add autogenerated models for frameworks related to Jenkins
|
2023-06-14 15:59:28 +02:00 |
|
Owen Mansel-Chan
|
5f72ce0935
|
Add stub implementations of flowCheckNodeSpecific
|
2023-06-14 14:46:35 +01:00 |
|
Owen Mansel-Chan
|
e0f7437d40
|
Sync dataflow library
|
2023-06-14 14:29:56 +01:00 |
|
Tony Torralba
|
7c4cdbf0d6
|
Remove badly generated models
|
2023-06-14 14:20:16 +02:00 |
|
Jami
|
35591113c2
|
Merge branch 'main' into jcogs33/shared-sink-kind-validation
|
2023-06-14 08:06:34 -04:00 |
|
Michael Nebel
|
afec9b05e9
|
Merge pull request #13147 from michaelnebel/csharp/entityframeworkrefactor
C#: Use synthetic global in the EntityFramework code instead of jump steps.
|
2023-06-14 13:47:56 +02:00 |
|
Tony Torralba
|
5e3d9d8136
|
Java: Model the Stapler framework
|
2023-06-14 12:34:52 +02:00 |
|
Tony Torralba
|
182513a981
|
Merge pull request #13235 from atorralba/atorralba/java/hudson-models
Java: Add Hudson models
|
2023-06-14 12:33:18 +02:00 |
|
Jean Helie
|
209f3e26d4
|
Merge pull request #13239 from github/tausbn/automodel-application-mode
Java: Add QL support for automodel application mode
|
2023-06-14 11:42:26 +02:00 |
|
Tony Torralba
|
8bafc22add
|
Replace open-url sink kinds with request-forgery
|
2023-06-14 09:59:59 +02:00 |
|
Tony Torralba
|
73d2ab7d66
|
Add change note
|
2023-06-14 09:58:30 +02:00 |
|
Tony Torralba
|
686c35e210
|
Add autogenerated models
|
2023-06-14 09:58:30 +02:00 |
|
Anders Schack-Mulligen
|
1a4fca334f
|
Merge pull request #13273 from aschackmull/dataflow/summarynode-refactor
Dataflow: Refactor FlowSummaryImpl to synthesize nodes independently from DataFlow::Node.
|
2023-06-14 09:38:36 +02:00 |
|
Anders Schack-Mulligen
|
2d616d494e
|
C#/Ruby: Add fields as per review comments.
|
2023-06-13 11:26:30 +02:00 |
|
Jeroen Ketema
|
c3ba206b6a
|
Merge pull request #13346 from jketema/inline-2
Update inline expectation tests to use parameterized module
|
2023-06-13 10:10:55 +02:00 |
|
Anders Schack-Mulligen
|
eec012d308
|
Java: Fix test
|
2023-06-12 13:18:13 +02:00 |
|
Jami Cogswell
|
9abe3e3da4
|
Shared: use a module as input to 'KindValidation'
|
2023-06-09 14:35:37 -04:00 |
|
Anders Schack-Mulligen
|
97b2bdaa9f
|
Java: Fix types of summary parameter nodes.
|
2023-06-09 15:39:28 +02:00 |
|
Anders Schack-Mulligen
|
254d60c826
|
Dataflow: Refactor FlowSummaryImpl to synthesize nodes independently from DataFlow::Node.
|
2023-06-09 15:27:17 +02:00 |
|
Anders Schack-Mulligen
|
59636c43ca
|
Dataflow: Rename two private predicates.
|
2023-06-09 15:27:17 +02:00 |
|
Stephan Brandauer
|
b38bc52019
|
Java: fix bug in ExcludedFromModeling Characteristic
|
2023-06-09 14:57:56 +02:00 |
|
Anders Schack-Mulligen
|
1b7bbf6320
|
Merge pull request #13083 from aschackmull/dataflow/typestrengthen
Dataflow: Strengthen tracked types.
|
2023-06-09 13:23:30 +02:00 |
|
Jeroen Ketema
|
49993b023e
|
Java: Rewrite inline expectation tests to use parameterized module
|
2023-06-09 10:42:17 +02:00 |
|
Anders Schack-Mulligen
|
44b09507ab
|
Merge pull request #13408 from aschackmull/java/loginjection-perf
Java: Add more negation context to reduce string ops and improve perf.
|
2023-06-09 08:44:27 +02:00 |
|
Anders Schack-Mulligen
|
68f1e40370
|
Java/C#: Add change notes.
|
2023-06-09 08:37:36 +02:00 |
|
Anders Schack-Mulligen
|
85d6b44d92
|
Java: Fix test output.
|
2023-06-09 08:37:36 +02:00 |
|
Anders Schack-Mulligen
|
d230509905
|
Dataflow: Address review comments.
|
2023-06-09 08:37:36 +02:00 |
|