github-actions[bot]
|
cdb8f67601
|
Post-release preparation for codeql-cli-2.12.0
|
2023-01-06 10:36:34 +00:00 |
|
Nick Rolfe
|
6e07076151
|
tweak wording in 2.12 release notes
|
2023-01-05 16:46:44 +00:00 |
|
github-actions[bot]
|
b6a8193785
|
Release preparation for version 2.12.0
|
2023-01-05 16:32:14 +00:00 |
|
Arthur Baars
|
035ad65e43
|
AlertSuppression: move library into util folder
|
2022-12-21 10:39:57 +01:00 |
|
Arthur Baars
|
a8be5d7274
|
AlertSuppression: add change notes
|
2022-12-19 17:02:52 +01:00 |
|
Arthur Baars
|
c176606be5
|
AlertSuppression: allow //lgtm comments to scope over the next line
|
2022-12-19 16:10:26 +01:00 |
|
Arthur Baars
|
016c7a8ca7
|
Merge pull request #11719 from aibaars/alert-suppression-shared
Shared AlertSuppression library
|
2022-12-19 16:04:44 +01:00 |
|
Erik Krogh Kristensen
|
f136651384
|
Merge pull request #11575 from erik-krogh/kernelLoad
Rb: add Kernel methods as sinks to path-injection
|
2022-12-19 15:09:21 +01:00 |
|
Arthur Baars
|
621a108846
|
Ruby: use shared AlertSuppression.qll
|
2022-12-19 12:26:06 +01:00 |
|
erik-krogh
|
db49cfb723
|
Merge branch 'main' into kernelLoad
|
2022-12-19 09:46:25 +01:00 |
|
erik-krogh
|
35e8d6afd4
|
move getACommonTld into a utility module without parameters
|
2022-12-18 17:23:45 +01:00 |
|
erik-krogh
|
26c5480ee6
|
share {js,rb}/regex/missing-regexp-anchor
|
2022-12-18 17:23:41 +01:00 |
|
erik-krogh
|
355499ea52
|
move getACommonTld to the shared pack
|
2022-12-17 17:26:18 +01:00 |
|
erik-krogh
|
f67d0bc8c0
|
put the shared HostnameRegexp code in the shared regex pack
|
2022-12-17 17:26:18 +01:00 |
|
Henry Mercer
|
30451ee950
|
Merge pull request #11681 from github/henrymercer/mergeback-3.8
Merge `rc/3.8` back to `main`
|
2022-12-16 17:43:12 +00:00 |
|
Tom Hvitved
|
5d9c64ba6f
|
Ruby: Model flow through initialize constructors
|
2022-12-14 12:57:39 +01:00 |
|
Henry Mercer
|
a3933fbf4f
|
Bump minor versions of packs we regularly release
|
2022-12-13 18:59:24 +00:00 |
|
Henry Mercer
|
7167f078be
|
Merge branch 'main' into henrymercer/mergeback-3.8
|
2022-12-13 18:40:53 +00:00 |
|
erik-krogh
|
e0045d2736
|
filter out string literals from the taint-sink meta query
|
2022-12-12 21:44:24 +01:00 |
|
erik-krogh
|
b3a9c1ca06
|
Py/JS/RB: Use instanceof in more places
|
2022-12-12 16:06:57 +01:00 |
|
github-actions[bot]
|
343b7b1c8b
|
Post-release preparation for codeql-cli-2.11.6
|
2022-12-11 18:15:04 +00:00 |
|
github-actions[bot]
|
0b2fb4f70a
|
Release preparation for version 2.11.6
|
2022-12-10 15:49:35 +00:00 |
|
Peter Stöckli
|
0d8c82009c
|
Merge branch 'main' into p--ruby-kernel-open-addition
|
2022-12-09 07:54:56 +01:00 |
|
erik-krogh
|
1a6e16f292
|
Merge branch 'main' into kernelLoad
|
2022-12-08 15:41:48 +01:00 |
|
Chris Smowton
|
49bc524fd0
|
Merge remote-tracking branch 'origin/rc/3.8' into smowton/admin/merge-rc38-into-main
|
2022-12-08 11:12:30 +00:00 |
|
erik-krogh
|
5849b2c98a
|
drive-by: simplify the imports in PathInjection.ql
|
2022-12-06 14:09:39 +01:00 |
|
github-actions[bot]
|
5e35785fd0
|
Post-release preparation for codeql-cli-2.11.5
|
2022-12-02 11:37:44 +00:00 |
|
github-actions[bot]
|
31ab22e3a0
|
Release preparation for version 2.11.5
|
2022-12-01 20:05:14 +00:00 |
|
erik-krogh
|
7dcb813ff3
|
remove two more claseses of FPs in rb/non-constant-kernel-open
|
2022-11-29 12:49:23 +01:00 |
|
Peter Stöckli
|
6b1865d2ca
|
Merge branch 'main' into p--ruby-kernel-open-addition
|
2022-11-29 10:19:36 +01:00 |
|
Peter Stöckli
|
5b6dd786c3
|
Add changes for NonConstantKernelOpenQuery
|
2022-11-29 10:00:57 +01:00 |
|
Peter Stöckli
|
315480824b
|
Fix KernelOpen qhelp
|
2022-11-29 10:00:57 +01:00 |
|
Peter Stöckli
|
d8752a0b12
|
Add additional sinks to the rb/kernel-open query
|
2022-11-29 10:00:56 +01:00 |
|
Nick Rolfe
|
8a94cabdbf
|
Merge pull request #11250 from github/nickrolfe/stack-trace-exposure
Ruby: add stack-trace exposure query
|
2022-11-28 10:45:59 +00:00 |
|
Nick Rolfe
|
1c407a28cd
|
Apply suggestions from code review
Co-authored-by: Harry Maclean <hmac@github.com>
|
2022-11-24 14:02:32 +00:00 |
|
Edoardo Pirovano
|
6c33ddcd47
|
Merge pull request #11349 from github/edoardo/2.11.4-mergeback
Merge `rc/3.8` into `main`
|
2022-11-21 18:08:27 +00:00 |
|
github-actions[bot]
|
5b14ebf22a
|
Post-release preparation for codeql-cli-2.11.4
|
2022-11-18 11:26:00 +00:00 |
|
github-actions[bot]
|
e105c13e77
|
Release preparation for version 2.11.4
|
2022-11-17 16:40:45 +00:00 |
|
erik-krogh
|
10fff4e2ef
|
Merge branch 'main' into rb-redosMod
|
2022-11-14 21:31:10 +01:00 |
|
Nick Rolfe
|
c660ea100b
|
Ruby: add changenote for rb/stack-trace-exposure
|
2022-11-14 12:26:40 +00:00 |
|
Nick Rolfe
|
b39e2ef71c
|
Ruby: add stacktrace exposure query
|
2022-11-14 12:26:40 +00:00 |
|
Nick Rolfe
|
0337ccb93a
|
Ruby: add change notes for Arel.sql / SqlConstruction changes
|
2022-11-10 14:11:14 +00:00 |
|
Nick Rolfe
|
4a98ef064e
|
Ruby: use the 'customizations' pattern for the SQL injection query
|
2022-11-10 11:51:47 +00:00 |
|
Asger F
|
859dc7beb7
|
Merge pull request #11024 from asgerf/rb/data-flow-layer-capture2
Ruby: expand DataFlow API
|
2022-11-09 15:06:03 +01:00 |
|
Erik Krogh Kristensen
|
c82410fd16
|
Merge pull request #10680 from erik-krogh/unsafeRbCmd
RB: add an unsafe-shell-command-construction query
|
2022-11-08 09:22:33 +01:00 |
|
Erik Krogh Kristensen
|
3f871a08e2
|
apply suggestions from doc review
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
|
2022-11-07 16:29:10 +01:00 |
|
erik-krogh
|
40e4359173
|
port the Ruby regex/redos queries to use the shared pack
|
2022-11-07 14:34:18 +01:00 |
|
github-actions[bot]
|
fca754bddd
|
Post-release preparation for codeql-cli-2.11.3
|
2022-11-05 14:30:48 +00:00 |
|
github-actions[bot]
|
508327235a
|
Release preparation for version 2.11.3
|
2022-11-04 20:16:23 +00:00 |
|
Arthur Baars
|
98f4c29913
|
Ruby: weak crypto: do not report weak hash algorithms
Weak hash algorithms such as MD5 and SHA1 are often
used in non security sensitive contexts and reporting
all uses is far too noisy.
|
2022-11-04 15:58:50 +01:00 |
|