Tom Hvitved
|
61b67640f4
|
Ruby: Adapt to parameterized SSA implementation
|
2022-08-31 11:45:15 +02:00 |
|
Tom Hvitved
|
760c7beb94
|
SSA: Sync files
|
2022-08-31 11:45:15 +02:00 |
|
Asger F
|
5ad6c05a9c
|
Merge pull request #10205 from asgerf/mad-generics
Support type variables in MaD typings
|
2022-08-30 18:07:39 +02:00 |
|
Asger F
|
dd44187aed
|
Sync files again
|
2022-08-30 14:08:33 +02:00 |
|
Asger F
|
d5d1365104
|
Synchronize ApiGraphModels.qll
|
2022-08-30 14:07:37 +02:00 |
|
erik-krogh
|
7fd426e748
|
print a correct range for ranges that doesn't contain any alpha-numeric chars
|
2022-08-30 13:57:11 +02:00 |
|
Erik Krogh Kristensen
|
8f0b999c31
|
Merge pull request #10207 from erik-krogh/fixRank
fix performance issue in the ReDoS query
|
2022-08-30 10:17:11 +02:00 |
|
erik-krogh
|
f47b097d7c
|
put a limit on the length of the equivalent range
|
2022-08-29 21:03:52 +02:00 |
|
erik-krogh
|
77949cbeb3
|
add context to the rankState predicate in ExponentialBackTracking.qll
|
2022-08-29 13:42:05 +02:00 |
|
Nick Rolfe
|
898689f550
|
Merge pull request #9896 from github/nickrolfe/hardcoded_code
Ruby: port js/hardcoded-data-interpreted-as-code
|
2022-08-26 13:49:25 +01:00 |
|
Nick Rolfe
|
52d46552af
|
Ruby: fix 'inefficient string comparison' alert
|
2022-08-26 09:58:22 +01:00 |
|
Nick Rolfe
|
95bf18fdc9
|
Ruby: make hex-escaped strings ("\xCD\xEF" etc.) sources of hardcoded data
|
2022-08-26 09:33:03 +01:00 |
|
erik-krogh
|
cc7a9ef97a
|
rename more acronyms
|
2022-08-25 20:52:27 +02:00 |
|
Erik Krogh Kristensen
|
ba1ad00d2a
|
Merge pull request #10062 from erik-krogh/redosPrefix
JS: use the shared regular expression libraries in `js/case-sensitive-middleware-path`
|
2022-08-25 12:57:16 +02:00 |
|
Nick Rolfe
|
acf5b11139
|
Merge remote-tracking branch 'origin/main' into nickrolfe/hardcoded_code
|
2022-08-25 11:44:55 +01:00 |
|
Ian Lynagh
|
bf6d9f8c23
|
Merge pull request #10161 from igfoo/igfoo/exec
Make a load of files non-executable
|
2022-08-25 10:05:39 +01:00 |
|
Anders Schack-Mulligen
|
c6f89aac0a
|
Merge pull request #10141 from aschackmull/ruby/perf-apigraph
Ruby: Perf fix for trackUseNode.
|
2022-08-25 10:22:07 +02:00 |
|
Ian Lynagh
|
501a9b3c6b
|
Make *.qll non-executable
|
2022-08-24 16:36:15 +01:00 |
|
Michael Nebel
|
761ed283b6
|
C#/Java/Ruby/Swift: Address review comments.
|
2022-08-24 09:58:54 +02:00 |
|
Michael Nebel
|
30d554503a
|
C#/Java: Fix some QL doc spelling typos.
|
2022-08-24 09:58:53 +02:00 |
|
Michael Nebel
|
160ae934af
|
C#/Java/Ruby/Swift: Fix typo in QL doc.
|
2022-08-24 09:58:53 +02:00 |
|
Michael Nebel
|
581824a9b4
|
C#/Java/Ruby/Swift: Fix various typos.
|
2022-08-24 09:58:53 +02:00 |
|
Michael Nebel
|
fbc0e6a1ec
|
Ruby: Sync files and make dummy negative summary implementation.
|
2022-08-24 09:58:52 +02:00 |
|
Anders Schack-Mulligen
|
b83e851ac6
|
Ruby: one more pragma
|
2022-08-23 16:04:29 +02:00 |
|
Anders Schack-Mulligen
|
0ea55a9581
|
Ruby: autoformat
|
2022-08-23 15:58:29 +02:00 |
|
Anders Schack-Mulligen
|
844e0129b6
|
Ruby: Perf fix for trackUseNode.
|
2022-08-23 15:50:54 +02:00 |
|
erik-krogh
|
5e3cb08ed2
|
rename stateInPumpableRegexp to stateInRelevantRegexp
|
2022-08-23 12:40:45 +02:00 |
|
erik-krogh
|
e89e0eb7fb
|
make some acronyms camelCase
|
2022-08-22 21:22:35 +02:00 |
|
erik-krogh
|
049af68bc2
|
restrict suffix-construction to relevant regexps
|
2022-08-21 20:35:39 +02:00 |
|
erik-krogh
|
bcf4c57060
|
Merge branch 'main' into redosPrefix
|
2022-08-19 19:22:49 +02:00 |
|
erik-krogh
|
d052b1e3c9
|
also support regular expressions without repetitions
|
2022-08-19 19:21:44 +02:00 |
|
Tom Hvitved
|
663096fe3a
|
Remove redundant overrides
|
2022-08-19 13:57:41 +02:00 |
|
Tom Hvitved
|
08a5b5dc73
|
Merge pull request #10089 from hvitved/ruby/local-source-nodes
Ruby: Reduce size of `isLocalSourceNode`
|
2022-08-18 12:02:35 +02:00 |
|
Nick Rolfe
|
a46e2b3f2f
|
Merge pull request #10056 from hmac/hmac/action-controller-response-body
Ruby: Recognise Rails render calls as HTTP responses
|
2022-08-18 10:02:17 +01:00 |
|
Tom Hvitved
|
682986c0a2
|
Merge pull request #10087 from hvitved/ruby/unknown-member-warning
Ruby: Get rid of warning in `getUnknownMember`
|
2022-08-18 10:50:24 +02:00 |
|
erik-krogh
|
473bc92e2d
|
move the PrefixConstruction module out of the ReDoSPruning module
|
2022-08-18 10:07:48 +02:00 |
|
Tom Hvitved
|
baa646e102
|
Ruby: Remove unused UnknownMember from API graphs
|
2022-08-18 09:40:02 +02:00 |
|
Harry Maclean
|
8f370b2457
|
Update ruby/ql/lib/change-notes/2022-08-16-action-controller-response-body.md
Co-authored-by: Nick Rolfe <nickrolfe@github.com>
|
2022-08-18 10:03:52 +12:00 |
|
Harry Maclean
|
70ec70940a
|
Merge pull request #8142 from github/hmac/incomplete-multi-char-sanitization
|
2022-08-18 10:02:39 +12:00 |
|
Erik Krogh Kristensen
|
e93ff8672c
|
Merge pull request #10075 from erik-krogh/depOld
delete old deprecations
|
2022-08-17 21:21:57 +02:00 |
|
Tom Hvitved
|
ed2ec1acc0
|
Ruby: Reduce size of isLocalSourceNode
|
2022-08-17 17:19:30 +02:00 |
|
Tom Hvitved
|
c307a12c20
|
Ruby: Get rid of warning in getUnknownMember
|
2022-08-17 16:22:11 +02:00 |
|
Alex Ford
|
d4d6657cb7
|
Merge pull request #10008 from alexrford/rb/log-injection
Ruby: Add `rb/log-injection` query
|
2022-08-17 15:01:22 +01:00 |
|
erik-krogh
|
6b9f01535b
|
change All to Most in the change-notes
|
2022-08-17 15:34:57 +02:00 |
|
erik-krogh
|
2622c78766
|
add change-notes
|
2022-08-17 13:55:16 +02:00 |
|
Tom Hvitved
|
355c1f5959
|
Merge pull request #10035 from hvitved/ssa/phi-reads
SSA: Improve use-use calculation using "phi read nodes"
|
2022-08-17 13:43:00 +02:00 |
|
Nick Rolfe
|
94a51142d0
|
Ruby: fix typo in internal predicate name
|
2022-08-17 11:05:39 +01:00 |
|
Harry Maclean
|
1f4dad4167
|
Update for rename of ReDoSUtil to NfaUtils
|
2022-08-17 16:03:49 +12:00 |
|
Harry Maclean
|
f1a546c4d6
|
Rename IncompleteMultiCharacterSanitization[Query]
|
2022-08-17 16:03:49 +12:00 |
|
Harry Maclean
|
f2384a6a8f
|
Ruby: Share more code with JS
|
2022-08-17 16:03:49 +12:00 |
|