Edoardo Pirovano
|
f25618eed6
|
Bump minor version of all packs
|
2022-04-08 15:38:58 +01:00 |
|
Edoardo Pirovano
|
ce82c54b94
|
Merge branch 'main' into edoardo/3.5-mergeback
|
2022-04-08 15:30:58 +01:00 |
|
github-actions[bot]
|
6af568b16d
|
Post-release preparation for codeql-cli-2.8.5
|
2022-04-01 16:22:14 +00:00 |
|
github-actions[bot]
|
ee746d20df
|
Release preparation for version 2.8.5
|
2022-04-01 10:39:31 +00:00 |
|
Alex Ford
|
882f78c6f9
|
Merge remote-tracking branch 'origin/main' into ruby/weak-cryptographic-algorithm
|
2022-03-31 17:17:46 +01:00 |
|
Tom Hvitved
|
40986bfcb1
|
Ruby: Fix broken import
|
2022-03-31 12:32:03 +02:00 |
|
Arthur Baars
|
15c54f6100
|
Merge pull request #8354 from aibaars/incomplete-url-string-sanitization
Incomplete url string sanitization
|
2022-03-31 10:59:51 +02:00 |
|
Arthur Baars
|
85c4daa2bf
|
Address comments
|
2022-03-28 13:15:32 +02:00 |
|
Arthur Baars
|
74aea81fe3
|
Ruby: refactor regex libraries
|
2022-03-24 11:37:02 +01:00 |
|
Arthur Baars
|
65f8f56095
|
Merge branch 'main' into incomplete-url-string-sanitization
|
2022-03-24 11:27:30 +01:00 |
|
Harry Maclean
|
91a7e9405c
|
Share HttpToFileAccessQuery between JS and Ruby
There's so little in this query that it may not be worth sharing, but
it's an interesting exercise in figuring out how we do it nicely.
|
2022-03-22 11:10:08 +13:00 |
|
Harry Maclean
|
ff1d96c922
|
Ruby: Add rb/http-to-file-access query
|
2022-03-22 11:09:08 +13:00 |
|
Harry Maclean
|
6c18e1d7ac
|
Merge pull request #8272 from hmac/hmac/tainted-format-string
|
2022-03-22 08:37:47 +13:00 |
|
github-actions[bot]
|
a3e74efc21
|
Post-release preparation for codeql-cli-2.8.4
|
2022-03-21 19:36:47 +00:00 |
|
github-actions[bot]
|
dedc8c2254
|
Release preparation for version 2.8.4
|
2022-03-21 13:25:49 +00:00 |
|
Alex Ford
|
c891c53835
|
Merge pull request #8395 from alexrford/ruby/clear-text-storage
Ruby: add `rb/clear-text-storage-sensitive-data` query
|
2022-03-21 10:05:39 +00:00 |
|
Harry Maclean
|
c73dc8ad0c
|
Ruby: Add change note for rb/tainted-format-string
|
2022-03-21 12:51:47 +13:00 |
|
Harry Maclean
|
10a411e5cc
|
Ruby: Remove duplicate CWE reference
|
2022-03-21 12:51:47 +13:00 |
|
Harry Maclean
|
d79a6ddcb2
|
Ruby: Improve qhelp for rb/tainted-format-string
|
2022-03-21 12:51:47 +13:00 |
|
Harry Maclean
|
0cfe37dff4
|
Share TaintedFormatString between Ruby and JS
|
2022-03-21 12:51:46 +13:00 |
|
Harry Maclean
|
f6215d4c7e
|
Ruby: Add rb/tainted-format-string query
|
2022-03-21 12:51:18 +13:00 |
|
Arthur Baars
|
bf888f0f0b
|
Merge remote-tracking branch 'upstream/main' into incomplete-url-string-sanitization
Conflicts:
config/identical-files.json
javascript/ql/src/Security/CWE-020/IncompleteUrlSubstringSanitization.ql
javascript/ql/src/Security/CWE-020/IncompleteUrlSubstringSanitization.qll
ruby/ql/src/queries/security/cwe-020/IncompleteUrlSubstringSanitization.qll
|
2022-03-18 16:09:20 +01:00 |
|
Arthur Baars
|
4a27928728
|
Ruby/JS add missing ^ in qhelp
|
2022-03-18 14:00:10 +01:00 |
|
Arthur Baars
|
f2ec5132ba
|
Apply suggestions from code review
Co-authored-by: Nick Rolfe <nickrolfe@github.com>
|
2022-03-16 14:46:34 +01:00 |
|
Arthur Baars
|
ab93b3784b
|
Merge remote-tracking branch 'upstream/main' into incomplete-hostname
|
2022-03-16 12:31:12 +01:00 |
|
Arthur Baars
|
6a74e761c8
|
Merge pull request #8398 from github/post-release-prep/codeql-cli-2.8.3
Post-release preparation for codeql-cli-2.8.3
|
2022-03-14 21:05:09 +01:00 |
|
Alex Ford
|
fc232ce55f
|
Ruby: changenote for rb/weak-cryptographic-algorithm
|
2022-03-13 21:25:28 +00:00 |
|
Alex Ford
|
94d5f3bb1f
|
Ruby: Add rb/weak-cryptographic-algorithm query
|
2022-03-13 21:25:28 +00:00 |
|
Alex Ford
|
446141ada3
|
Ruby: qhelp for rb/weak-cryptographic-algorithm
|
2022-03-13 21:25:12 +00:00 |
|
Arthur Baars
|
cf4b834536
|
Address comments
|
2022-03-11 14:25:34 +01:00 |
|
Erik Krogh Kristensen
|
69353bb014
|
patch upper-case acronyms to be PascalCase
|
2022-03-11 11:10:33 +01:00 |
|
github-actions[bot]
|
3a5ebbb861
|
Post-release preparation for codeql-cli-2.8.3
|
2022-03-11 09:23:34 +00:00 |
|
github-actions[bot]
|
6b194bc55f
|
Release preparation for version 2.8.3
|
2022-03-10 19:43:58 +00:00 |
|
Alex Ford
|
0b73088ed4
|
Ruby: link to sink in rb/clear-text-storage-sensitive-data message
|
2022-03-10 17:38:52 +00:00 |
|
Alex Ford
|
fda2b56e20
|
Ruby: move rb/clear-text-storage-sensitive-data location from sink to source
|
2022-03-10 17:38:52 +00:00 |
|
Alex Ford
|
4618000567
|
Ruby: move an import into CleartextStorage.ql
|
2022-03-10 17:38:52 +00:00 |
|
Alex Ford
|
0e2709f809
|
Ruby: changenote for rb/clear-text-storage-sensitive-data
|
2022-03-10 17:38:52 +00:00 |
|
Alex Ford
|
0070e30377
|
Ruby: Add rb/clear-text-storage-sensitive-data query
|
2022-03-10 17:38:52 +00:00 |
|
Arthur Baars
|
747c7f6b5e
|
JS/Ruby: share implementation of IncompleteUrlSubstringSanitization query
|
2022-03-09 12:11:14 +01:00 |
|
Arthur Baars
|
a1873cc803
|
Ruby: IncompleteUrlSubstringSanitization.ql
|
2022-03-07 16:17:32 +01:00 |
|
Arthur Baars
|
c9fa1fb5bb
|
Ruby: copy JS version of IncompleteUrlSubstringSanitization.ql
|
2022-03-07 16:17:08 +01:00 |
|
Arthur Baars
|
98f56f4d60
|
Js/Ruby: Share IncompleteHostnameRegExp.ql
|
2022-03-07 16:10:08 +01:00 |
|
Arthur Baars
|
9e8930c192
|
Ruby: IncompleteHostnameRegExp.ql
|
2022-03-07 16:10:08 +01:00 |
|
Arthur Baars
|
832c9c4b0b
|
Ruby: copy IncompleteHostnameRegExp files from JavaScript
|
2022-03-07 16:10:07 +01:00 |
|
Arthur Baars
|
169f65526e
|
Merge pull request #8292 from aibaars/api-graphs-private
Ruby: ApiGraphs: use private imports
|
2022-03-02 00:35:46 +01:00 |
|
Tamás Vajk
|
94cb5c2be4
|
Merge pull request #8296 from github/post-release-prep/codeql-cli-2.8.2
Post-release preparation for codeql-cli-2.8.2
|
2022-03-01 11:57:36 +01:00 |
|
github-actions[bot]
|
980f822983
|
Post-release preparation for codeql-cli-2.8.2
|
2022-03-01 09:24:30 +00:00 |
|
Arthur Baars
|
7e6ef7ac74
|
Ruby: ApiGraphs: use private imports
|
2022-03-01 10:24:19 +01:00 |
|
CodeQL CI
|
0f125d1e8a
|
Merge pull request #8234 from asgerf/ruby/meta-queries
Approved by nickrolfe
|
2022-02-25 12:46:15 +00:00 |
|
github-actions[bot]
|
20fe22c8c8
|
Release preparation for version 2.8.2
|
2022-02-24 14:57:08 +00:00 |
|