Erik Krogh Kristensen
|
8d556ed1e1
|
Update python/ql/lib/semmle/python/security/BadTagFilterQuery.qll
Co-authored-by: Rasmus Wriedt Larsen <rasmuswriedtlarsen@gmail.com>
|
2021-09-28 23:04:28 +02:00 |
|
Erik Krogh Kristensen
|
99ed4a1a89
|
add a bad-tag-filter query for Python and JavaScript
|
2021-09-21 15:04:03 +02:00 |
|
Erik Krogh Kristensen
|
c40ffab093
|
make isStartState public in ReDoSUtil
|
2021-09-21 12:14:21 +02:00 |
|
Rasmus Wriedt Larsen
|
c7c8e2f3e3
|
Merge branch 'main' into promote-sqlalchemy
|
2021-09-21 09:36:07 +02:00 |
|
Rasmus Wriedt Larsen
|
c34d6d1162
|
Python: Add query to handle SQLAlchemy TextClause Injection
instead of doing this via taint-steps. See description in code/tests.
|
2021-09-02 10:19:57 +02:00 |
|
Erik Krogh Kristensen
|
1ad204d89e
|
make after and TState private in ReDoSUtil
|
2021-09-02 09:15:43 +02:00 |
|
Erik Krogh Kristensen
|
a3289fabe1
|
sync ReDoSUtil with python
|
2021-09-01 12:47:06 +02:00 |
|
Erik Krogh Kristensen
|
f5a1a12435
|
support case insensitive regexps in the ReDoS queries
|
2021-08-30 09:59:33 +02:00 |
|
Erik Krogh Kristensen
|
0cc19d914e
|
use toUnicode in ReDoSUtil.qll
|
2021-08-25 22:21:43 +02:00 |
|
Andrew Eisenberg
|
3660c64328
|
Packaging: Rafactor Python core libraries
Extract the external facing `qll` files into the codeql/python-all
query pack.
|
2021-08-24 13:23:45 -07:00 |
|