Sebastian Bauersfeld
|
5cf320d553
|
Add corresponding taint steps.
|
2022-08-19 17:33:35 +07:00 |
|
Sebastian Bauersfeld
|
b0fbe3658d
|
Add java.lang.String taint tests.
|
2022-08-19 17:33:35 +07:00 |
|
Erik Krogh Kristensen
|
4f93f2b9ba
|
Merge pull request #10076 from erik-krogh/ql-for-ql-fixes
various QL-for-QL fixes
|
2022-08-18 15:46:48 +02:00 |
|
Anders Schack-Mulligen
|
61a2c0dab5
|
Merge pull request #10084 from aschackmull/java/numericcasttainted-barrier
Java: Move sink-constraints into the configuration in NumericCastTainted.ql.
|
2022-08-18 15:22:00 +02:00 |
|
erik-krogh
|
9e7c0c6ab9
|
revert changing imports in java/
|
2022-08-18 10:19:12 +02:00 |
|
Anders Schack-Mulligen
|
37e5f0438c
|
Java: Add change note.
|
2022-08-18 09:19:32 +02:00 |
|
erik-krogh
|
4bc10f9b5c
|
explicitly import required frameworks that were previously implicitly imported
|
2022-08-18 08:40:46 +02:00 |
|
Anders Schack-Mulligen
|
f6eccd390e
|
Java: Move sink-constraints into the configuration.
|
2022-08-17 15:06:55 +02:00 |
|
Anders Schack-Mulligen
|
c3ba632a32
|
Java: Add some type-based sanitizers to SensitiveInfoLog.ql.
|
2022-08-17 14:54:28 +02:00 |
|
Anders Schack-Mulligen
|
6e495ba6e5
|
Merge pull request #10068 from aschackmull/java/summarizedcallable-split
Java: Make synthesized method bodies disjoint from source code.
|
2022-08-17 14:13:56 +02:00 |
|
erik-krogh
|
14d83ab1b5
|
make the framework imports in FlowSources.qll private
|
2022-08-17 13:50:08 +02:00 |
|
erik-krogh
|
8066e39d07
|
delete some redundant imports
|
2022-08-17 13:50:04 +02:00 |
|
erik-krogh
|
b7b80fe176
|
reintroduce redundant cast in synced file
|
2022-08-17 13:34:22 +02:00 |
|
erik-krogh
|
ffb65d054e
|
delete redundant inline casts
|
2022-08-17 13:34:22 +02:00 |
|
erik-krogh
|
2e44fba67d
|
add explicit this
|
2022-08-17 13:33:31 +02:00 |
|
Anders Schack-Mulligen
|
c034a1e268
|
Java: Fix test.
|
2022-08-17 12:46:35 +02:00 |
|
Anders Schack-Mulligen
|
27f76330be
|
Java: Fix models.
|
2022-08-17 12:46:09 +02:00 |
|
Anders Schack-Mulligen
|
857b473503
|
Java: Delete duplicate tests.
|
2022-08-17 12:44:42 +02:00 |
|
Joe Farebrother
|
7c188a6b96
|
Apply doc suggestions
|
2022-08-17 10:35:16 +01:00 |
|
Joe Farebrother
|
7989ba3391
|
Replace a tainttracking instance with local flow
|
2022-08-17 10:35:16 +01:00 |
|
Joe Farebrother
|
5afc0b0c15
|
Add security severity
|
2022-08-17 10:35:15 +01:00 |
|
Joe Farebrother
|
bf32b5a8fd
|
Reiview suggestions - add doc comment, reword description, simplify a part
|
2022-08-17 10:35:15 +01:00 |
|
Joe Farebrother
|
a62bb8e115
|
Add additional test case
|
2022-08-17 10:35:15 +01:00 |
|
Joe Farebrother
|
960a4e58a0
|
Add change note
|
2022-08-17 10:35:14 +01:00 |
|
Joe Farebrother
|
c152a27a68
|
Reword docs
|
2022-08-17 10:35:14 +01:00 |
|
Joe Farebrother
|
4d0957711b
|
Reduce FPs from empty arrays
|
2022-08-17 10:35:14 +01:00 |
|
Joe Farebrother
|
c0a1300955
|
Improve initializedWthConstants to no longer need a workaround
|
2022-08-17 10:35:13 +01:00 |
|
Joe Farebrother
|
f8f21c7ee6
|
Move static init vector query and tests from experimental to main
|
2022-08-17 10:35:13 +01:00 |
|
Jami
|
dd23d48ad2
|
Merge pull request #9939 from jcogs33/android-debug-query-inline-tests
Java: query to detect android:debuggable attribute enabled
|
2022-08-16 10:07:13 -04:00 |
|
Sid Shankar
|
1e1e2318b7
|
Merge pull request #10052 from github/task/fix-broken-links
Docs: Replace HTTP broken links to equivalent HTTPS resources
|
2022-08-16 08:45:08 -04:00 |
|
Anders Schack-Mulligen
|
df40ccd129
|
Java: Make synthesized method bodies disjoint from source code.
|
2022-08-16 13:36:39 +02:00 |
|
Erik Krogh Kristensen
|
fd5b8896df
|
Merge pull request #10063 from erik-krogh/fixRbDep
re-deprecate ReDoSUtil in ruby
|
2022-08-16 13:27:52 +02:00 |
|
Alex Ford
|
d02ad51d74
|
Merge pull request #10032 from github/post-release-prep/codeql-cli-2.10.3
Post-release preparation for codeql-cli-2.10.3
|
2022-08-16 12:04:07 +01:00 |
|
erik-krogh
|
8e6a36256c
|
import the non-deprecated NfaUtils in the overly-large-range query
|
2022-08-16 11:21:43 +02:00 |
|
Anders Schack-Mulligen
|
28e4224ab1
|
Merge pull request #10023 from aschackmull/java/numbertype-perf
Java: Minor perf improvement.
|
2022-08-16 09:52:55 +02:00 |
|
Erik Krogh Kristensen
|
f106e064fa
|
Merge pull request #9422 from erik-krogh/refacReDoS
Refactorizations of the ReDoS libraries
|
2022-08-16 09:32:08 +02:00 |
|
Jami Cogswell
|
07e141c5be
|
added commas to help file
|
2022-08-15 15:50:00 -04:00 |
|
Jami Cogswell
|
4986cc8458
|
update isDebuggable predicate
|
2022-08-15 15:50:00 -04:00 |
|
Jami Cogswell
|
f529cc43bc
|
updated lib change note name
|
2022-08-15 15:50:00 -04:00 |
|
Jami Cogswell
|
29acce1e93
|
remove extraneous unit test
|
2022-08-15 15:50:00 -04:00 |
|
Jami Cogswell
|
4c2b05ce8c
|
adding change-note for android manifest library
|
2022-08-15 15:50:00 -04:00 |
|
Jami Cogswell
|
b779f9f935
|
added casting
|
2022-08-15 15:50:00 -04:00 |
|
Jami Cogswell
|
c010f92811
|
simplified predicates, removed overridden getFile predicate
|
2022-08-15 15:50:00 -04:00 |
|
Jami Cogswell
|
6e10fcf519
|
added predicates in the AndroidManifest library and adjusted tests
|
2022-08-15 15:50:00 -04:00 |
|
Jami Cogswell
|
229324fde0
|
updated overview section of help file; also added 'App Manifest Overview' to references
|
2022-08-15 15:50:00 -04:00 |
|
Jami Cogswell
|
3714a98403
|
add reference to help file
|
2022-08-15 15:50:00 -04:00 |
|
Jami Cogswell
|
ead36822be
|
update change note based on review comment
|
2022-08-15 15:50:00 -04:00 |
|
Jami Cogswell
|
f961540979
|
added change note
|
2022-08-15 15:50:00 -04:00 |
|
Jami Cogswell
|
af0a663ee8
|
remove commented-out code in Test.java file
|
2022-08-15 15:50:00 -04:00 |
|
Jami Cogswell
|
d1a23ad78c
|
updated to getRelativePath with %build%
|
2022-08-15 15:50:00 -04:00 |
|