Chris Smowton
|
92d1becf08
|
Merge pull request #6474 from github/yo-h-patch-1
Java: add `org.json` package to known frameworks
|
2021-08-17 14:09:39 +01:00 |
|
Chris Smowton
|
c52a51e5c8
|
Merge pull request #6454 from smowton/smowton/admin/change-note-wording
Java: Elaborate change note a little
|
2021-08-17 14:08:04 +01:00 |
|
CodeQL CI
|
92804a3cc3
|
Merge pull request #6487 from erik-krogh/moreJquerySinks
Approved by asgerf
|
2021-08-17 11:46:24 +01:00 |
|
Cornelius Riemenschneider
|
341dad5f73
|
Merge pull request #6490 from criemen/criemen/delete-flaky-test
JS: Delete flaky test.
|
2021-08-17 12:33:03 +02:00 |
|
CodeQL CI
|
e3cdc4522e
|
Merge pull request #6450 from asgerf/js/query-suffix-convention2
Approved by erik-krogh
|
2021-08-17 11:31:21 +01:00 |
|
Tom Hvitved
|
44ff623d8c
|
Merge pull request #5508 from edvraa/deserializers
deserialization sinks
|
2021-08-17 11:41:52 +02:00 |
|
Cornelius Riemenschneider
|
59b3d55b9a
|
JS: Delete flaky test.
codeql-cli/v2.6.0
|
2021-08-17 10:58:39 +02:00 |
|
Erik Krogh Kristensen
|
cc2a267b07
|
recognize array elements from JQuery objects as DOM values
|
2021-08-16 22:35:57 +02:00 |
|
Mathias Vorreiter Pedersen
|
221a259938
|
Merge pull request #6486 from ihsinme/ihsinme-patch-textFix
correction of the error text
|
2021-08-16 14:49:33 +02:00 |
|
ihsinme
|
6988912b72
|
Update UndefinedOrImplementationDefinedBehavior.ql
|
2021-08-16 15:20:00 +03:00 |
|
Erik Krogh Kristensen
|
46959234b7
|
Merge pull request #6288 from erik-krogh/emptyRedos
JS/Python: Fix FP in redos related to empty lookaheads
|
2021-08-16 13:48:22 +02:00 |
|
Asger Feldthaus
|
0047536337
|
JS: Add change note
|
2021-08-16 13:22:43 +02:00 |
|
ihsinme
|
c63dff639c
|
Update UndefinedOrImplementationDefinedBehavior.expected
|
2021-08-16 14:15:10 +03:00 |
|
ihsinme
|
74f372d547
|
Update UndefinedOrImplementationDefinedBehavior.ql
|
2021-08-16 14:11:28 +03:00 |
|
Tamás Vajk
|
166a6b02f6
|
Merge pull request #6268 from tamasvajk/feature/generic-type-name
C#: Remove type args/params from generic type names in extractor
|
2021-08-16 12:22:16 +02:00 |
|
Chris Smowton
|
497f36796c
|
Merge pull request #6483 from Marcono1234/marcono1234/callable-string-signature-doc
Java: Improve Callable.getStringSignature() documentation
|
2021-08-16 11:05:59 +01:00 |
|
Erik Krogh Kristensen
|
e962a7c77c
|
Update python/ql/src/semmle/python/RegexTreeView.qll
Co-authored-by: yoff <lerchedahl@gmail.com>
|
2021-08-16 11:24:05 +02:00 |
|
Marcono1234
|
48872b4588
|
Java: Improve Callable.getStringSignature() documentation
|
2021-08-14 19:58:55 +02:00 |
|
Sarita Iyer
|
57ff8e7138
|
Merge pull request #6473 from github/sarita-iyer/codeql-packs-vscode
Added article for working with codeQL packs in VS Code
|
2021-08-12 16:08:00 -04:00 |
|
Sarita Iyer
|
a373ac8332
|
Update period at end of quote
|
2021-08-12 15:42:23 -04:00 |
|
Sarita Iyer
|
eb2ef23d56
|
Apply suggestions from code review
Co-authored-by: Ethan Palm <56270045+ethanpalm@users.noreply.github.com>
Co-authored-by: Andrew Eisenberg <aeisenberg@github.com>
|
2021-08-12 14:57:13 -04:00 |
|
Sarita Iyer
|
d1190dc5f2
|
Switch from object to element, and clarify package cache functionality
|
2021-08-12 10:41:20 -04:00 |
|
Shati Patel
|
1707fb8821
|
Merge pull request #6475 from github/correct-link-syntax
Fix markup in `metadata-for-codeql-queries.rst`
|
2021-08-12 09:36:18 +01:00 |
|
Asger Feldthaus
|
a6c389698e
|
JS: Fix DomBasedXssQuery.qll
|
2021-08-12 09:31:24 +02:00 |
|
Asger Feldthaus
|
fd027451b1
|
JS: Fix StoresXss example query
|
2021-08-12 09:30:43 +02:00 |
|
Asger Feldthaus
|
020d65befc
|
Fix StoredXssTypeTracking example query
|
2021-08-12 09:30:43 +02:00 |
|
Asger Feldthaus
|
cb0075f15a
|
JS: Remove use of deprecated API
|
2021-08-12 09:30:43 +02:00 |
|
Asger Feldthaus
|
3a6da34454
|
JS: Add missing QLdoc
|
2021-08-12 09:30:43 +02:00 |
|
Asger Feldthaus
|
71930f93f1
|
JS: Fix cleartext logging
|
2021-08-12 09:30:43 +02:00 |
|
Asger Feldthaus
|
abb819ed88
|
JS: Fix insecure randomness
|
2021-08-12 09:30:43 +02:00 |
|
Asger Feldthaus
|
5638a33199
|
JS: Remove obsolete module prefix
|
2021-08-12 09:30:43 +02:00 |
|
Asger Feldthaus
|
f6da030572
|
JS: Migrate to *Query.qll convention
|
2021-08-12 09:30:18 +02:00 |
|
CodeQL CI
|
8fe2a43fd9
|
Merge pull request #6433 from asgerf/js/tainted-url-suffix
Approved by erik-krogh
|
2021-08-12 00:28:46 -07:00 |
|
James Fletcher
|
3bd918972e
|
fix markup
|
2021-08-12 08:16:20 +01:00 |
|
yo-h
|
bd3a24d568
|
Java: add org.json package to known frameworks
|
2021-08-11 20:03:32 -04:00 |
|
Sarita Iyer
|
186e011a4b
|
Added codeql packs info for use in VS code
|
2021-08-11 15:47:27 -04:00 |
|
Alexandre Boulgakov
|
00466e4bb0
|
Merge pull request #6464 from sashabu/sashabu/auto
C++: Expose trailing return type presence.
|
2021-08-11 18:43:39 +01:00 |
|
Chris Smowton
|
7a2704373f
|
Merge pull request #5943 from joefarebrother/java-stub
[Java] Add stubbing script
|
2021-08-11 16:11:53 +01:00 |
|
Alexandre Boulgakov
|
490498899b
|
C++: Expose trailing return type presence.
|
2021-08-11 16:04:07 +01:00 |
|
Geoffrey White
|
3f72a1abea
|
Merge pull request #6471 from MathiasVP/fix-fp-in-incorrect-allocation-error-handling
C++: Fix false-positive in 'cpp/incorrect-allocation-error-handling'
|
2021-08-11 15:56:55 +01:00 |
|
CodeQL CI
|
c8ded7ebf6
|
Merge pull request #6459 from erik-krogh/oreq
Approved by asgerf
|
2021-08-11 07:40:13 -07:00 |
|
Mathias Vorreiter Pedersen
|
8d594dbf08
|
Update cpp/ql/test/query-tests/Security/CWE/CWE-570/test.cpp
Co-authored-by: Geoffrey White <40627776+geoffw0@users.noreply.github.com>
|
2021-08-11 16:18:18 +02:00 |
|
Mathias Vorreiter Pedersen
|
0d1884d7a6
|
C++: Fix FP and accept test changes.
|
2021-08-11 15:38:57 +02:00 |
|
Mathias Vorreiter Pedersen
|
c2b1da0010
|
C++: Add FP testcase with an 'new' that has a 'std::nothrow&' parameter, but not a 'noexcept' specifier. This case was previously not reported because of the 'noexcept' specifier, and apparently the 'std::nothrow' case was broken all along.
|
2021-08-11 15:38:03 +02:00 |
|
Mathias Vorreiter Pedersen
|
89ce25f247
|
Merge pull request #6083 from ihsinme/ihsinme-patch-275
CPP: Add query for CWE-783 Operator Precedence Logic Error When Use Bitwise Or Logical Operations
|
2021-08-11 14:40:09 +02:00 |
|
ihsinme
|
6d24047626
|
Update OperatorPrecedenceLogicErrorWhenUseBitwiseOrLogicalOperations.ql
|
2021-08-11 14:34:20 +03:00 |
|
Chris Smowton
|
d45d58804b
|
Merge pull request #6466 from github/workflow/coverage/update
Update CSV framework coverage reports
|
2021-08-11 07:56:55 +01:00 |
|
github-actions[bot]
|
5db82651fe
|
Add changed framework coverage reports
|
2021-08-11 00:13:37 +00:00 |
|
Joe Farebrother
|
7462180dcd
|
Improve handling or array types
|
2021-08-10 16:52:38 +01:00 |
|
Tamas Vajk
|
243424063a
|
Add pragma inline to getMember/Method/Callable
|
2021-08-10 13:25:56 +02:00 |
|