Erik Krogh Kristensen
|
99e98419dc
|
add support for error values in an axios client request
|
2021-05-11 11:24:21 +02:00 |
|
Erik Krogh Kristensen
|
52991dc4a1
|
rewrite the axios model to use API graphs
|
2021-05-11 11:23:51 +02:00 |
|
Erik Krogh Kristensen
|
54f191cfe3
|
add support for rejected promise values in API graphs
|
2021-05-11 11:23:03 +02:00 |
|
Anders Schack-Mulligen
|
744c495ac2
|
Merge pull request #5824 from JLLeitschuh/feat/JLL/guava_first_non_null
[Java] Add support for com.google.common.base.MoreObjects#firstNonNull
|
2021-05-11 09:42:20 +02:00 |
|
AlexDenisov
|
2905bb8b9a
|
Merge pull request #5861 from AlexDenisov/alexdenisov/adjust-user-defined-literals-test
C++: Adjust user-defined literals test' expectations
|
2021-05-11 09:31:54 +02:00 |
|
Anders Schack-Mulligen
|
7d6a497136
|
Merge pull request #5857 from dbartol/container/work
Java: Fix QLDoc for `Container.toString()`
|
2021-05-11 08:37:41 +02:00 |
|
Dave Bartolomeo
|
f85aff869c
|
Java: Fix PR feedback
|
2021-05-10 16:37:23 -04:00 |
|
Mathias Vorreiter Pedersen
|
5016c6436a
|
Merge pull request #5859 from MathiasVP/fix-fp-in-comparison-with-wider-type
C++: Fix false positive in `cpp/comparison-with-wider-type`
|
2021-05-10 17:58:31 +02:00 |
|
Chris Smowton
|
0afe22d60c
|
Merge pull request #5710 from p0wn4j/jsch-os-injection
[Java] CWE-078: Add JSch lib OS Command Injection sink
|
2021-05-10 16:12:00 +01:00 |
|
Mathias Vorreiter Pedersen
|
d55db836cb
|
C++: Remove implied conjunct.
|
2021-05-10 16:13:54 +02:00 |
|
Tom Hvitved
|
498f9b2547
|
Merge pull request #5848 from hvitved/csharp/trap-key-escape
C#: Escape IDs in TRAP label definitions
|
2021-05-10 16:13:13 +02:00 |
|
Mathias Vorreiter Pedersen
|
51d04cb5b3
|
C++: Correct test annotation.
|
2021-05-10 15:30:35 +02:00 |
|
Mathias Vorreiter Pedersen
|
c0b65314be
|
C++: Fix false positive by restricting _both_ the old (unconverted) expression _and_ all of the conversions.
|
2021-05-10 15:18:42 +02:00 |
|
Mathias Vorreiter Pedersen
|
c7cd75437f
|
C++: Add testcase demonstrating false positive from conversions.
|
2021-05-10 14:58:33 +02:00 |
|
CodeQL CI
|
a3d17a1437
|
Merge pull request #5769 from erik-krogh/libXss
Approved by esbena
|
2021-05-10 05:58:07 -07:00 |
|
Tom Hvitved
|
7f1f2b4dd3
|
C#: Fix GetHashCode/Equals on EscapingTextWriter
|
2021-05-10 13:05:51 +02:00 |
|
Alex Denisov
|
dcdd54593e
|
C++: Adjust user-defined literals test' expectations
|
2021-05-10 13:03:40 +02:00 |
|
CodeQL CI
|
097b6e5e33
|
Merge pull request #5794 from erik-krogh/rxPipe
Approved by asgerf
|
2021-05-10 02:06:34 -07:00 |
|
Erik Krogh Kristensen
|
d913668943
|
move hasPathWithoutUnmatchedReturn to Configuration.qll
|
2021-05-10 10:55:33 +02:00 |
|
Erik Krogh Kristensen
|
b4e35f54d9
|
fix typo
|
2021-05-10 10:48:43 +02:00 |
|
Erik Krogh Kristensen
|
646bf99489
|
rewrite the qhelp to focus more on documenting unsafe functions
|
2021-05-10 10:48:40 +02:00 |
|
CodeQL CI
|
b1f28afcbd
|
Merge pull request #5741 from asgerf/js/more-cheat-sheet
Approved by erik-krogh
|
2021-05-10 01:34:56 -07:00 |
|
Mathias Vorreiter Pedersen
|
474b337eeb
|
C++: Add change-note.
|
2021-05-10 10:22:44 +02:00 |
|
Mathias Vorreiter Pedersen
|
c91ed80e6c
|
C++: Fix false positive by computing range of the converted expression.
|
2021-05-10 10:12:43 +02:00 |
|
Mathias Vorreiter Pedersen
|
7ac7830973
|
C++: Add testcase with false positive involving a conversion on the large-expression side of the comparison.
|
2021-05-10 10:11:31 +02:00 |
|
Erik Krogh Kristensen
|
3fe5dd0f35
|
add comment about filtering away jQuery from the source
|
2021-05-10 10:05:18 +02:00 |
|
Tom Hvitved
|
8b465e86e0
|
Merge pull request #5820 from hvitved/csharp/cfg/constructor-same-compilation
C#: Improve CFG for constructors when there are multiple implementations
|
2021-05-10 09:23:16 +02:00 |
|
Dave Bartolomeo
|
d9f243d18a
|
Java: Fix QLDoc for Container.toString()
Fixes #5828
The QLDoc was just too specific about the default implementation. I've improved the wording.
|
2021-05-08 11:14:02 -04:00 |
|
Hayk Andriasyan
|
fd88b72101
|
Delete JSchOSInjection.qhelp
|
2021-05-08 12:51:15 +04:00 |
|
Geoffrey White
|
65ac5b862d
|
Merge pull request #5847 from MathiasVP/improve-wrong-in-detecting-and-handling-memory-allocation-errors
Improve wrong in detecting and handling memory allocation errors
|
2021-05-07 17:39:04 +01:00 |
|
Mathias Vorreiter Pedersen
|
2241d7b359
|
Merge pull request #5616 from geoffw0/unsigneddiff2
C++: Improve cpp/unsigned-difference-expression-compared-zero
|
2021-05-07 17:58:53 +02:00 |
|
Geoffrey White
|
75edcf0b4f
|
Merge branch 'main' into unsigneddiff2
|
2021-05-07 16:35:16 +01:00 |
|
Geoffrey White
|
69468514f0
|
Update cpp/ql/src/Security/CWE/CWE-191/UnsignedDifferenceExpressionComparedZero.ql
Co-authored-by: Mathias Vorreiter Pedersen <mathiasvp@github.com>
|
2021-05-07 16:26:42 +01:00 |
|
Geoffrey White
|
91be483c57
|
Update cpp/ql/src/Security/CWE/CWE-191/UnsignedDifferenceExpressionComparedZero.ql
Co-authored-by: Mathias Vorreiter Pedersen <mathiasvp@github.com>
|
2021-05-07 16:26:36 +01:00 |
|
Geoffrey White
|
fc96c1c400
|
Update cpp/ql/src/Security/CWE/CWE-191/UnsignedDifferenceExpressionComparedZero.ql
Co-authored-by: Mathias Vorreiter Pedersen <mathiasvp@github.com>
|
2021-05-07 16:26:23 +01:00 |
|
Geoffrey White
|
5db6abe2f4
|
Update cpp/ql/src/Security/CWE/CWE-191/UnsignedDifferenceExpressionComparedZero.ql
Co-authored-by: Mathias Vorreiter Pedersen <mathiasvp@github.com>
|
2021-05-07 16:22:48 +01:00 |
|
Geoffrey White
|
894f5d523c
|
Update cpp/ql/src/Security/CWE/CWE-191/UnsignedDifferenceExpressionComparedZero.ql
Co-authored-by: Mathias Vorreiter Pedersen <mathiasvp@github.com>
|
2021-05-07 16:19:48 +01:00 |
|
Felicity Chapman
|
10e76ff28f
|
Merge pull request #5831 from github/3893-code-scanning
Update CodeQL CLI article to use different query suite example
|
2021-05-07 12:37:47 +01:00 |
|
Mathias Vorreiter Pedersen
|
fc7d9c2c09
|
C++: Fix missing result by properly specifying that the function with unknown code actually didn't throw an exception.
|
2021-05-07 12:34:38 +02:00 |
|
Mathias Vorreiter Pedersen
|
90e8368258
|
C++: Properly handle conversions in convertedExprMayThrow. This recursive implementation idea is stolen from convertedExprMightOverflow in SimpleRangeAnalysis.
|
2021-05-07 12:31:43 +02:00 |
|
Mathias Vorreiter Pedersen
|
7adb7b67f2
|
C++: Add false positive testcase involving conversions.
|
2021-05-07 12:19:19 +02:00 |
|
Anders Schack-Mulligen
|
8783746516
|
Merge pull request #5774 from atorralba/promote-xpath-injection
Java: Promote XPath Injection query from experimental
|
2021-05-07 12:04:49 +02:00 |
|
Mathias Vorreiter Pedersen
|
88e6cbaacd
|
C++: Include Assignments in exprMayThrow and accept test changes.
|
2021-05-07 11:49:25 +02:00 |
|
Mathias Vorreiter Pedersen
|
80d41d9fe5
|
C++: Add false positive testcase involving assignments.
|
2021-05-07 11:48:09 +02:00 |
|
Tom Hvitved
|
ca89560849
|
C#: Remove unnecessary !
|
2021-05-07 11:42:53 +02:00 |
|
Mathias Vorreiter Pedersen
|
08fa611700
|
C++: Avoid calling SwitchCase.getAStmt for performance reasons. This turns out to not be needed as the statements inside the switch case will get picked up by the BlockStmt.getAStmt case already.
|
2021-05-07 11:18:50 +02:00 |
|
Tony Torralba
|
2a501956b3
|
Mark a MISSING test result as suggested in code review
|
2021-05-07 11:17:51 +02:00 |
|
Tony Torralba
|
b69be30b88
|
Fix imports as suggested in code review
|
2021-05-07 11:07:06 +02:00 |
|
Erik Krogh Kristensen
|
b53759c5a0
|
corrections after code review
|
2021-05-06 22:49:25 +02:00 |
|
CodeQL CI
|
7a7586488a
|
Merge pull request #5833 from erik-krogh/filterStep
Approved by esbena
|
2021-05-06 13:47:23 -07:00 |
|