Joe Farebrother
|
8d201626e1
|
Add documentation
|
2024-01-29 16:25:38 +00:00 |
|
Joe Farebrother
|
6081f18089
|
Add unit tests + make some fixes
|
2024-01-29 16:25:37 +00:00 |
|
Joe Farebrother
|
5dd0addfc2
|
Add sensitive text flow query
|
2024-01-29 16:25:36 +00:00 |
|
Joe Farebrother
|
031bd8bd0c
|
Merge pull request #15281 from joefarebrother/android-sensitive-ui-notif
Java: Add query for exposure of sensitive information to android notifiactions
|
2024-01-26 16:42:55 +00:00 |
|
erik-krogh
|
73e3fada44
|
add missing </p>
|
2024-01-25 12:14:10 +01:00 |
|
erik-krogh
|
05a59d2a94
|
apply suggestions from doc review
|
2024-01-25 11:20:46 +01:00 |
|
erik-krogh
|
158ff0da0a
|
add a trailing slash to the folder check in the QHelp for java/path-injection
|
2024-01-23 14:46:02 +01:00 |
|
erik-krogh
|
00dadeb3bf
|
delete the markdown file again
|
2024-01-23 12:57:15 +01:00 |
|
erik-krogh
|
57e0b3cceb
|
iterate on the java/path-injection qhelp
|
2024-01-23 12:56:43 +01:00 |
|
erik-krogh
|
4958c19c67
|
move the examples for the qhelps into an example/ folder
|
2024-01-23 12:56:23 +01:00 |
|
erik-krogh
|
6b66f5cbc5
|
check in the TaintedPath qhelp as markdown to get pretty diffs
|
2024-01-23 12:56:22 +01:00 |
|
Joe Farebrother
|
1190352b67
|
Add qhelp
|
2024-01-23 09:51:40 +00:00 |
|
Joe Farebrother
|
143ce0b94a
|
Add sensitive notification query
|
2024-01-23 09:51:37 +00:00 |
|
Ed Minnix
|
55da62e9cf
|
Remove stray comma
Co-authored-by: Felicity Chapman <felicitymay@github.com>
|
2024-01-08 11:09:11 -05:00 |
|
Edward Minnix III
|
2440075402
|
Remove off-topic reference
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com>
|
2024-01-08 09:39:10 -05:00 |
|
Edward Minnix III
|
3816271b3e
|
Remove redundant CWE link
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com>
|
2024-01-08 09:39:10 -05:00 |
|
Ed Minnix
|
2eff6b351c
|
Add comment
|
2024-01-08 09:39:09 -05:00 |
|
Ed Minnix
|
16bb19e176
|
Add OWASP and CERT references
|
2024-01-08 09:39:08 -05:00 |
|
Ed Minnix
|
9f974415c0
|
Add references to CWE-454 (External Initialization of Trusted Variables)
|
2024-01-08 09:39:07 -05:00 |
|
Ed Minnix
|
97b29bb965
|
Add Java Tutorial reference
|
2024-01-08 09:39:06 -05:00 |
|
Edward Minnix III
|
938d52b86f
|
Docs review suggestions
Co-authored-by: Felicity Chapman <felicitymay@github.com>
|
2024-01-08 09:39:05 -05:00 |
|
Ed Minnix
|
e14be0e971
|
Add BAD markers to samples
|
2024-01-08 09:39:04 -05:00 |
|
Edward Minnix III
|
18e8a27fca
|
Reworded name and description
|
2024-01-08 09:38:51 -05:00 |
|
Edward Minnix III
|
1f37e70d83
|
Fix typos
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com>
|
2024-01-08 09:38:51 -05:00 |
|
Ed Minnix
|
51006aa088
|
Formatting fix
|
2024-01-08 09:38:50 -05:00 |
|
Ed Minnix
|
4fc6f710a4
|
Fix alert message
|
2024-01-08 09:38:48 -05:00 |
|
Ed Minnix
|
1550f5df2a
|
Environment variable injection query documentation
|
2024-01-08 09:38:47 -05:00 |
|
Ed Minnix
|
818c5de8d5
|
security-severity metadata
|
2024-01-08 09:38:46 -05:00 |
|
Ed Minnix
|
8ed3f3c865
|
Move to library
|
2024-01-08 09:38:44 -05:00 |
|
Ed Minnix
|
b482b36b5f
|
Initial ProcessBuilder support
|
2024-01-08 09:38:41 -05:00 |
|
Ed Minnix
|
93025cc8cf
|
Argument injection initial commit
|
2024-01-08 09:38:40 -05:00 |
|
Tony Torralba
|
8ad787f3b8
|
Java: Generelize MaybeBrokenCryptoAlgorithmQuery.qll
|
2023-12-22 10:15:40 +01:00 |
|
Ed Minnix
|
8051cfcef5
|
Fix tests and fix getStringValue method
|
2023-12-21 22:48:08 -05:00 |
|
Tony Torralba
|
0524289a73
|
Update java/ql/src/Security/CWE/CWE-327/MaybeBrokenCryptoAlgorithm.ql
|
2023-12-18 08:50:10 +01:00 |
|
Ed Minnix
|
02581a3850
|
Move class for getProperty method call to Properties.qll
|
2023-12-15 11:09:08 -05:00 |
|
Ed Minnix
|
83c6ece405
|
Move weak hashing into MaybeBrokenCryptoAlgorithm
|
2023-12-15 11:09:07 -05:00 |
|
Ed Minnix
|
cb0ea350b5
|
Improve docs
|
2023-12-15 11:09:07 -05:00 |
|
Ed Minnix
|
0efca8200d
|
Weak Hashing query wording
|
2023-12-15 11:09:07 -05:00 |
|
Ed Minnix
|
93cf5b8eb9
|
Weak Hashing Property initial query
|
2023-12-15 11:09:07 -05:00 |
|
Edward Minnix III
|
06eef93f89
|
Docs review suggestions
|
2023-12-11 11:18:40 -05:00 |
|
Edward Minnix III
|
ce20c4ae03
|
Docs review suggestions
Co-authored-by: Ben Ahmady <32935794+subatoi@users.noreply.github.com>
|
2023-12-11 11:18:40 -05:00 |
|
Ed Minnix
|
3ca039bc8f
|
Rename to InsecureRandomness
|
2023-12-11 11:18:40 -05:00 |
|
Edward Minnix III
|
4678302edb
|
Update query metadata
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com>
|
2023-12-11 11:18:39 -05:00 |
|
Ed Minnix
|
e69ff7b601
|
Move to library and add docs
|
2023-12-11 11:18:38 -05:00 |
|
Ed Minnix
|
9f986ca527
|
Add Weak Randomness Query
|
2023-12-11 11:18:38 -05:00 |
|
Max Schaefer
|
ca334021ad
|
Merge pull request #14793 from github/max-schaefer/tainted-path-qhelp
Java: Improve QHelp for `java/path-injection` to mention less disruptive fixes.
|
2023-11-16 14:09:55 +00:00 |
|
Max Schaefer
|
a5e7ef424e
|
Revert "Add additional example."
This reverts commit 947b094387.
|
2023-11-16 11:54:16 +00:00 |
|
Max Schaefer
|
143e1680bd
|
Apply suggestions from code review
Co-authored-by: Ben Ahmady <32935794+subatoi@users.noreply.github.com>
|
2023-11-16 11:42:35 +00:00 |
|
Max Schaefer
|
947b094387
|
Add additional example.
|
2023-11-16 10:06:19 +00:00 |
|
Max Schaefer
|
009d58034f
|
Address suggestions from review.
|
2023-11-16 10:05:54 +00:00 |
|