Arthur Baars
|
80ebfed226
|
Merge pull request #336 from github/improve-getTemplateFile
Improve `RenderCall#getTemplateFile` performance and accuracy
|
2021-10-12 20:21:12 +02:00 |
|
Arthur Baars
|
06e91c1182
|
Merge pull request #322 from github/request-without-validation
rb/request-without-cert-validation
|
2021-10-12 20:19:11 +02:00 |
|
Nick Rolfe
|
ceef9762a7
|
Fix comment typo
Co-authored-by: Alex Ford <alexrford@users.noreply.github.com>
|
2021-10-12 17:45:34 +01:00 |
|
Arthur Baars
|
398ed4c0c9
|
Merge pull request #338 from github/aibaars/update-grammar
Update tree-sitter-ruby
|
2021-10-12 18:39:34 +02:00 |
|
Arthur Baars
|
bb5da92577
|
Update src/unsupported_feature.rb with a feature that is still unsupported
|
2021-10-12 18:11:00 +02:00 |
|
Arthur Baars
|
8c9d3b88df
|
Update dbscheme stats
|
2021-10-12 17:48:59 +02:00 |
|
Arthur Baars
|
0dc3ea5ed1
|
Add test-cases for forward arguments and endless methods
|
2021-10-12 17:32:01 +02:00 |
|
Arthur Baars
|
e44064cda7
|
Add forward parameter/arguments to AST
|
2021-10-12 17:31:31 +02:00 |
|
Nick Rolfe
|
ecc9f07c50
|
Merge pull request #311 from github/nickrolfe/oj
Consider Oj.load a sink for unsafe deserialization
|
2021-10-12 16:17:08 +01:00 |
|
Alex Ford
|
e35ad020d5
|
ql format
|
2021-10-12 15:56:00 +01:00 |
|
Alex Ford
|
909cdacb1a
|
remove cast to StringlikeLiteral
|
2021-10-12 15:27:26 +01:00 |
|
Alex Ford
|
44499cab51
|
replace an abstract predicate
|
2021-10-12 15:27:10 +01:00 |
|
Alex Ford
|
9640af0b8c
|
Merge pull request #339 from github/rc-workflows
enable actions workflows for rc branches
|
2021-10-12 12:23:47 +01:00 |
|
Alex Ford
|
f870c38e4c
|
enable actions workflows for rc branches
|
2021-10-12 10:47:27 +01:00 |
|
Alex Ford
|
48f3d48a11
|
add some test cases for checking against spurious flow into ERB templates
|
2021-10-12 10:37:22 +01:00 |
|
Arthur Baars
|
2a7f3fbfaf
|
Add upgrade script
|
2021-10-12 11:36:10 +02:00 |
|
Nick Rolfe
|
8e14b6582d
|
Remove unused predicate
|
2021-10-11 18:15:41 +01:00 |
|
Alex Ford
|
7270fe0ee7
|
slightly limit viable template files from render calls
|
2021-10-11 17:12:08 +01:00 |
|
Alex Ford
|
cdfee1f27d
|
better RenderCall#getTemplateFile performance and accuracy
|
2021-10-11 16:46:10 +01:00 |
|
Arthur Baars
|
fac4df203a
|
Update tree-sitter-ruby
|
2021-10-11 12:53:16 +02:00 |
|
Nick Rolfe
|
f500e5b2d7
|
Use Expr::getValueText
|
2021-10-08 16:41:06 +01:00 |
|
Calum Grant
|
958fbc7992
|
Merge pull request #316 from github/calumgrant/readme
Update README.md
|
2021-10-08 10:36:07 +01:00 |
|
Alex Ford
|
9dedb0540e
|
Merge pull request #312 from github/rb/stored-xss-1
Implement `rb/stored-xss` query
|
2021-10-08 10:33:11 +01:00 |
|
Alex Ford
|
16ab4da812
|
Update ql/lib/codeql/ruby/security/XSS.qll
Co-authored-by: Harry Maclean <hmac@github.com>
|
2021-10-07 20:03:07 +01:00 |
|
Nick Rolfe
|
eafe22ef93
|
Merge remote-tracking branch 'origin/main' into nickrolfe/oj
|
2021-10-07 16:40:36 +01:00 |
|
Arthur Baars
|
2a32b59840
|
Merge pull request #331 from github/aibaars/remove-unsafe
Remove use of 'unsafe'
|
2021-10-07 16:58:59 +02:00 |
|
Alex Ford
|
de01770612
|
update test output
|
2021-10-07 15:50:35 +01:00 |
|
Arthur Baars
|
439d873564
|
Remove use of 'unsafe'
|
2021-10-07 16:38:29 +02:00 |
|
Alex Ford
|
168e67dd6d
|
deduplicate string constantQualifiedName(ConstantWriteAccess) as string ConstantWriteAccess#getQualifiedName
|
2021-10-07 15:30:36 +01:00 |
|
Alex Ford
|
5b38e06765
|
Rename ActiveRecordModelClass#methodMayAccessField() as ActiveRecordModelClass#getAPotentialFieldAccessMethod()
|
2021-10-07 15:30:36 +01:00 |
|
Alex Ford
|
3bdc680434
|
Drop a comment that is no longer relevant
|
2021-10-07 15:30:36 +01:00 |
|
Alex Ford
|
8262247ed7
|
Minor simplification of finderMethodName predicate
|
2021-10-07 15:30:36 +01:00 |
|
Alex Ford
|
eb8c48d10f
|
Remove some unused predicates
|
2021-10-07 15:30:36 +01:00 |
|
Alex Ford
|
c9edbd98d5
|
Update ql/lib/codeql/ruby/frameworks/ActiveRecord.qll
Co-authored-by: Harry Maclean <hmac@github.com>
|
2021-10-07 15:30:36 +01:00 |
|
Alex Ford
|
e4fe1d5c13
|
check for superclass method definitions in ActiveRecordModelClass#methodMayAccessField
|
2021-10-07 15:30:36 +01:00 |
|
Alex Ford
|
fb5cfcc9b0
|
OrmTracking goes through or expressions
|
2021-10-07 15:30:36 +01:00 |
|
Alex Ford
|
be018cc97f
|
update ActionController tests
|
2021-10-07 15:30:36 +01:00 |
|
Alex Ford
|
955080234b
|
partial support for rails layouts
|
2021-10-07 15:30:36 +01:00 |
|
Alex Ford
|
8e1b48e607
|
StoredXSS.qhelp
|
2021-10-07 15:30:36 +01:00 |
|
Alex Ford
|
182a926eeb
|
rename some example files
|
2021-10-07 15:30:36 +01:00 |
|
Alex Ford
|
1929a95e89
|
format
|
2021-10-07 15:30:36 +01:00 |
|
Alex Ford
|
6065e29aba
|
Fix performance issues related to a x-product between ActiveRecordModelInstantiation and MethodCall
|
2021-10-07 15:30:36 +01:00 |
|
Alex Ford
|
43a49689d7
|
reorganize ActiveRecord field access heuristics
|
2021-10-07 15:30:36 +01:00 |
|
Alex Ford
|
8f81eaa79c
|
format
|
2021-10-07 15:30:36 +01:00 |
|
Alex Ford
|
b2434950d3
|
abstract away some ActiveRecord specific parts of XSS.qll
|
2021-10-07 15:30:36 +01:00 |
|
Alex Ford
|
6a32c0cde0
|
update XSS tests
|
2021-10-07 15:30:36 +01:00 |
|
Alex Ford
|
6dc3ce335b
|
make rb/stored-xss track ActiveRecord db accesses
|
2021-10-07 15:30:36 +01:00 |
|
Alex Ford
|
f6dd6bb00c
|
expand ActiveRecord modelling to cover how to access fields
|
2021-10-07 15:30:36 +01:00 |
|
Alex Ford
|
eb5f26ce06
|
duplicate DataFlow implementation
|
2021-10-07 15:30:36 +01:00 |
|
Alex Ford
|
a2084f813e
|
rb/stored-xss structure and initial implementation (FileSystemReadAccess sources)
|
2021-10-07 15:30:36 +01:00 |
|