Anders Schack-Mulligen
|
7974e3ad38
|
Merge pull request #5883 from zbazztian/consider-boxed-booleans-to-avoid-xxe-fps
Consider boxed booleans to avoid false positives for XXE.ql
|
2021-05-12 12:51:22 +02:00 |
|
Sebastian Bauersfeld
|
b05512a958
|
Add change notes.
|
2021-05-12 16:58:24 +07:00 |
|
Sebastian Bauersfeld
|
bf4d88175c
|
Consider boxed booleans to avoid false positives for XXE.ql
|
2021-05-12 16:40:00 +07:00 |
|
Geoffrey White
|
8f152b7380
|
Merge pull request #5877 from MathiasVP/detect-more-abs-in-overflow-library
C++: Detect more uses of `abs`
|
2021-05-12 10:02:12 +01:00 |
|
Tom Hvitved
|
fc121e1cbd
|
Merge pull request #5865 from tamasvajk/feature/remove-base-class-dependency-id
C#: Remove base class from type IDs in trap files
|
2021-05-12 10:30:31 +02:00 |
|
Anders Schack-Mulligen
|
a247ae4357
|
Merge pull request #5843 from JLLeitschuh/feat/JLL/improve_kryo_support
[Java] Fix Kryo FP & Kryo 5 Support
|
2021-05-12 09:52:24 +02:00 |
|
Anders Schack-Mulligen
|
74ae2e0857
|
Merge pull request #5773 from hvitved/dataflow/aggressive-caching
Data flow: Cache most language-dependent predicates
|
2021-05-12 09:41:55 +02:00 |
|
Tamas Vajk
|
8e371fd05a
|
Adjust expected IR test file
|
2021-05-11 21:54:05 +02:00 |
|
Mathias Vorreiter Pedersen
|
948f1d8e34
|
C++: Add testcase with INTMAX_MIN.
|
2021-05-11 19:43:21 +02:00 |
|
Geoffrey White
|
d7e560c611
|
Merge pull request #5767 from ihsinme/ihsinme-patch-268
CPP: Add query for CWE-1126: Declaration of Variable with Unnecessarily Wide Scope
|
2021-05-11 15:24:25 +01:00 |
|
Mathias Vorreiter Pedersen
|
3e21f479a9
|
C++: Add change-note.
|
2021-05-11 14:58:48 +02:00 |
|
Tom Hvitved
|
d66506b0a3
|
Data flow: Rename {Argument,Parameter}NodeExt to {Arg,Param}Node
|
2021-05-11 14:40:10 +02:00 |
|
Mathias Vorreiter Pedersen
|
48e783184c
|
C++: Fix false positive by recognizing more absolute value functions in Overflow.qll
|
2021-05-11 14:30:28 +02:00 |
|
Jonathan Leitschuh
|
0d9a85ca6b
|
Update java/change-notes/2021-05-05-kryo-improvements.md
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2021-05-11 08:29:50 -04:00 |
|
Mathias Vorreiter Pedersen
|
24d8abd2c2
|
C++: Add false positive testcase when an absolute value is used in comparison.
|
2021-05-11 14:27:53 +02:00 |
|
CodeQL CI
|
922b276fac
|
Merge pull request #5728 from asgerf/js/source-sink-queries
Approved by erik-krogh
codeql-cli/v2.5.5
|
2021-05-11 05:04:47 -07:00 |
|
Tamas Vajk
|
717070c7e4
|
Fix/cleanup passed and default arguments values
|
2021-05-11 13:11:35 +02:00 |
|
yoff
|
a7f97895ac
|
Merge pull request #5863 from erik-krogh/printReg
JS: add printAst.ql support for regular expressions
|
2021-05-11 12:45:49 +02:00 |
|
yoff
|
0e5a2c4573
|
Merge pull request #5442 from jorgectf/jorgectf/python/redos
Python: Add Regular Expression Injection query
|
2021-05-11 12:11:35 +02:00 |
|
yoff
|
549c9eee1a
|
Merge pull request #5739 from RasmusWL/share-sensitive-data-modeling
Python/JS: Share sensitive data modeling
|
2021-05-11 11:53:59 +02:00 |
|
CodeQL CI
|
a87731115a
|
Merge pull request #5860 from max-schaefer/js/improve-sql-modelling
Approved by asgerf
|
2021-05-11 02:24:52 -07:00 |
|
CodeQL CI
|
beb66fc4db
|
Merge pull request #5719 from asgerf/js/nestjs
Approved by esbena
|
2021-05-11 02:08:27 -07:00 |
|
Anders Schack-Mulligen
|
744c495ac2
|
Merge pull request #5824 from JLLeitschuh/feat/JLL/guava_first_non_null
[Java] Add support for com.google.common.base.MoreObjects#firstNonNull
|
2021-05-11 09:42:20 +02:00 |
|
AlexDenisov
|
2905bb8b9a
|
Merge pull request #5861 from AlexDenisov/alexdenisov/adjust-user-defined-literals-test
C++: Adjust user-defined literals test' expectations
|
2021-05-11 09:31:54 +02:00 |
|
Anders Schack-Mulligen
|
7d6a497136
|
Merge pull request #5857 from dbartol/container/work
Java: Fix QLDoc for `Container.toString()`
|
2021-05-11 08:37:41 +02:00 |
|
Dave Bartolomeo
|
f85aff869c
|
Java: Fix PR feedback
|
2021-05-10 16:37:23 -04:00 |
|
Mathias Vorreiter Pedersen
|
5016c6436a
|
Merge pull request #5859 from MathiasVP/fix-fp-in-comparison-with-wider-type
C++: Fix false positive in `cpp/comparison-with-wider-type`
|
2021-05-10 17:58:31 +02:00 |
|
Jonathan Leitschuh
|
d27316eb3e
|
Apply suggestions from code review
Co-authored-by: Marcono1234 <Marcono1234@users.noreply.github.com>
|
2021-05-10 11:55:31 -04:00 |
|
Chris Smowton
|
0afe22d60c
|
Merge pull request #5710 from p0wn4j/jsch-os-injection
[Java] CWE-078: Add JSch lib OS Command Injection sink
|
2021-05-10 16:12:00 +01:00 |
|
Tamas Vajk
|
dd86da3f24
|
C#: Remove base class from type IDs in trap files
|
2021-05-10 17:06:10 +02:00 |
|
Tamas Vajk
|
31ac6442e8
|
C#: Fix default parameter value generation in case of error symbols
|
2021-05-10 17:03:08 +02:00 |
|
Mathias Vorreiter Pedersen
|
d55db836cb
|
C++: Remove implied conjunct.
|
2021-05-10 16:13:54 +02:00 |
|
Tom Hvitved
|
498f9b2547
|
Merge pull request #5848 from hvitved/csharp/trap-key-escape
C#: Escape IDs in TRAP label definitions
|
2021-05-10 16:13:13 +02:00 |
|
Mathias Vorreiter Pedersen
|
51d04cb5b3
|
C++: Correct test annotation.
|
2021-05-10 15:30:35 +02:00 |
|
Mathias Vorreiter Pedersen
|
c0b65314be
|
C++: Fix false positive by restricting _both_ the old (unconverted) expression _and_ all of the conversions.
|
2021-05-10 15:18:42 +02:00 |
|
Mathias Vorreiter Pedersen
|
c7cd75437f
|
C++: Add testcase demonstrating false positive from conversions.
|
2021-05-10 14:58:33 +02:00 |
|
CodeQL CI
|
a3d17a1437
|
Merge pull request #5769 from erik-krogh/libXss
Approved by esbena
|
2021-05-10 05:58:07 -07:00 |
|
yoff
|
78370cf63f
|
Update python/ql/src/experimental/semmle/python/frameworks/Stdlib.qll
|
2021-05-10 14:53:40 +02:00 |
|
Erik Krogh Kristensen
|
504c34ed2c
|
use shouldPrint to filter out regular expressions from other files
|
2021-05-10 14:51:13 +02:00 |
|
Erik Krogh Kristensen
|
d6f9e37e39
|
add printAst.ql support for regular expressions
|
2021-05-10 13:31:00 +02:00 |
|
ihsinme
|
9e5a38debd
|
Update DeclarationOfVariableWithUnnecessarilyWideScope.expected
|
2021-05-10 14:17:40 +03:00 |
|
ihsinme
|
d3c6093f37
|
Update test.c
|
2021-05-10 14:16:38 +03:00 |
|
ihsinme
|
c8f2937df9
|
Update DeclarationOfVariableWithUnnecessarilyWideScope.ql
|
2021-05-10 14:16:11 +03:00 |
|
Tom Hvitved
|
7f1f2b4dd3
|
C#: Fix GetHashCode/Equals on EscapingTextWriter
|
2021-05-10 13:05:51 +02:00 |
|
Alex Denisov
|
dcdd54593e
|
C++: Adjust user-defined literals test' expectations
|
2021-05-10 13:03:40 +02:00 |
|
Max Schaefer
|
8f91e9eba0
|
JavaScript: Model chaining calls in sqlite3.
|
2021-05-10 10:58:58 +01:00 |
|
Asger F
|
f4e636dcd6
|
Update javascript/ql/src/semmle/javascript/frameworks/ClassValidator.qll
Co-authored-by: Esben Sparre Andreasen <esbena@github.com>
|
2021-05-10 10:08:10 +01:00 |
|
CodeQL CI
|
097b6e5e33
|
Merge pull request #5794 from erik-krogh/rxPipe
Approved by asgerf
|
2021-05-10 02:06:34 -07:00 |
|
Erik Krogh Kristensen
|
d913668943
|
move hasPathWithoutUnmatchedReturn to Configuration.qll
|
2021-05-10 10:55:33 +02:00 |
|
Erik Krogh Kristensen
|
b4e35f54d9
|
fix typo
|
2021-05-10 10:48:43 +02:00 |
|