Alex Ford
|
a5d8db6317
|
Ruby: fix qldoc
|
2023-06-07 15:55:28 +01:00 |
|
Alex Ford
|
57508b2b3b
|
ruby: Limit rack PotentialResponseNode to things that look like they occur in a rack application
|
2023-06-07 15:55:05 +01:00 |
|
Alex Ford
|
b62a02f0ad
|
ruby: remove unused field
|
2023-06-01 14:01:40 +01:00 |
|
Alex Ford
|
23e22799a9
|
ruby: rack - modelling -> modeling
|
2023-06-01 14:01:40 +01:00 |
|
Alex Ford
|
24635df1a3
|
ruby: add some qldoc for rack
|
2023-06-01 14:01:40 +01:00 |
|
Alex Ford
|
40da7d45c2
|
ruby: make a predicate private
|
2023-06-01 14:01:40 +01:00 |
|
Alex Ford
|
4905a70e21
|
Ruby: update rack test output
|
2023-06-01 14:01:40 +01:00 |
|
Alex Ford
|
19664879c8
|
ruby: slightly expand a TODO
|
2023-06-01 14:01:40 +01:00 |
|
Alex Ford
|
a5a15f3804
|
Ruby: restructure rack model
|
2023-06-01 14:01:40 +01:00 |
|
Alex Ford
|
b2958f87b2
|
ruby: rack - add redirect responses
|
2023-06-01 14:01:40 +01:00 |
|
Alex Ford
|
c3ab867595
|
ruby: start restructuring rack
|
2023-06-01 14:01:40 +01:00 |
|
Alex Ford
|
f8d2cbbe79
|
ruby: rack responses implement are HTTP responses
|
2023-06-01 14:01:39 +01:00 |
|
Alex Ford
|
c87c266871
|
ruby: add Rack::ResponseNode#getAStatusCode
|
2023-06-01 14:01:39 +01:00 |
|
Alex Ford
|
e7e0cf5cb3
|
ruby: add Rack::ResponseNode class
|
2023-06-01 14:01:39 +01:00 |
|
Arthur Baars
|
c211b704f3
|
Merge pull request #13272 from github/post-release-prep/codeql-cli-2.13.3
Post-release preparation for codeql-cli-2.13.3
|
2023-05-31 15:33:12 +02:00 |
|
Michael Nebel
|
2266e28583
|
Merge pull request #13262 from michaelnebel/flowsummary/refactorgetcomponentstack
C#: Re-factor getComponent.
|
2023-05-31 08:22:44 +02:00 |
|
Arthur Baars
|
490d22d123
|
Merge remote-tracking branch 'upstream/main' into post-release-prep/codeql-cli-2.13.3
|
2023-05-30 21:31:28 +02:00 |
|
Arthur Baars
|
d91fa2d038
|
Ruby: add print-cfg query
|
2023-05-30 17:30:04 +02:00 |
|
Asger F
|
3831dc7785
|
Merge pull request #13288 from asgerf/rb/super-and-flow-through
Ruby: two bug fixes
|
2023-05-26 15:04:52 +02:00 |
|
Asger F
|
cfaa27ab5d
|
Ruby: change note
|
2023-05-26 14:44:00 +02:00 |
|
yoff
|
af1f4c30fb
|
Merge pull request #13299 from asgerf/rb/meta-query-summarised-callable-sites
Ruby/Python: add meta-queries for calls to summarised callables
|
2023-05-26 13:27:56 +02:00 |
|
Arthur Baars
|
e0466900ad
|
Merge pull request #12992 from Sim4n6/ruby-UBV
[Ruby] Add Unicode Bypass Validation query, test and help file
|
2023-05-26 13:00:21 +02:00 |
|
Alex Ford
|
baabd2d1fa
|
Merge pull request #12832 from maikypedia/maikypedia/pg-sqli
Ruby: Add SQL Injection Sinks
|
2023-05-26 11:36:17 +01:00 |
|
Michael Nebel
|
915042a881
|
Minor cleanup and sync files.
|
2023-05-26 12:25:00 +02:00 |
|
Michael Nebel
|
58fcbc136c
|
Ruby: Re-factor getComponent.
|
2023-05-26 12:25:00 +02:00 |
|
Asger F
|
1c7f6dc32e
|
Ruby: add meta-query for calls to summarized callables
|
2023-05-26 11:34:23 +02:00 |
|
Alex Ford
|
609319da20
|
ruby: update TaintStep.ql test output
|
2023-05-25 17:53:01 +01:00 |
|
Asger F
|
9e8cef5e1b
|
Ruby: fix type-tracking flow-through for new->initialize calls
|
2023-05-25 15:03:38 +02:00 |
|
Asger F
|
93678e5d36
|
Ruby: fix name of super calls in singleton methods
|
2023-05-25 15:03:34 +02:00 |
|
Sim4n6
|
52dd247a81
|
Removed redundant cast
|
2023-05-25 11:55:13 +01:00 |
|
Sim4n6
|
09c97ce0da
|
Added one more example to the qhelp
|
2023-05-25 09:41:22 +01:00 |
|
Sim4n6
|
7d68f6afc9
|
added ActiveSupport::Multibyte::Chars normalize() sink
|
2023-05-25 09:21:55 +01:00 |
|
Sim4n6
|
d772bb213a
|
Added three more Unicode Normalization sinks
|
2023-05-25 03:10:00 +01:00 |
|
Maiky
|
40450a2792
|
typo
|
2023-05-24 17:02:48 +02:00 |
|
github-actions[bot]
|
d2e192020b
|
Post-release preparation for codeql-cli-2.13.3
|
2023-05-24 11:26:12 +00:00 |
|
Tom Hvitved
|
05f3934042
|
Merge pull request #13251 from hvitved/ruby/call-graph-self-param
Ruby: Include both `self` parameters and SSA definitions in call graph construction
|
2023-05-24 11:10:34 +02:00 |
|
Asger F
|
818753e922
|
Merge pull request #13265 from asgerf/rb/delete-name-clash
Ruby: fix some name clashes between summarized callables
|
2023-05-24 11:08:56 +02:00 |
|
Tom Hvitved
|
b486a4d52c
|
Merge pull request #13255 from hvitved/ruby/ssa-param-capture-input
Ruby: Include underlying SSA parameter definition in `localFlowSsaParamCaptureInput`
|
2023-05-24 10:40:54 +02:00 |
|
Asger F
|
8bd6f6c450
|
Ruby: change note
|
2023-05-24 10:22:22 +02:00 |
|
Asger F
|
6d1a4451fb
|
Ruby: update a test expectation
|
2023-05-24 10:15:51 +02:00 |
|
Maiky
|
27c1e47ece
|
Update ruby/ql/lib/change-notes/2023-05-06-pg.md
Co-authored-by: Jorge <46056498+jorgectf@users.noreply.github.com>
|
2023-05-24 01:44:51 +02:00 |
|
Maiky
|
8dca585207
|
Expected
|
2023-05-23 20:04:34 +02:00 |
|
Maiky
|
ad5355a04a
|
Pg Library, change note and Frameworks.qll
|
2023-05-23 19:49:03 +02:00 |
|
Arthur Baars
|
e33f3a6668
|
Merge pull request #13154 from aibaars/sync-dbscheme-py
JS/Ruby/QL/Python: sync dbscheme fragments
|
2023-05-23 19:14:29 +02:00 |
|
Sim4n6
|
90c174de4e
|
Updated the .expected file accordingly
|
2023-05-23 17:36:50 +01:00 |
|
Asger F
|
0592c8ba99
|
Ruby: avoid name clash for "assoc" summary
|
2023-05-23 17:34:19 +02:00 |
|
Asger F
|
50a7b21928
|
Ruby: fix a name clash for summaries called "delete"
|
2023-05-23 16:49:17 +02:00 |
|
Tom Hvitved
|
eaa84cb819
|
Ruby: Include underlying SSA parameter definition in localFlowSsaParamCaptureInput
|
2023-05-23 13:56:29 +02:00 |
|
Tom Hvitved
|
349de77474
|
Ruby: Include both self parameters and SSA definitions in call graph construction
|
2023-05-23 12:28:06 +02:00 |
|
Erik Krogh Kristensen
|
50cb5ea184
|
Merge pull request #13164 from erik-krogh/polyQhelp
ReDoS: add another example to the qhelp in poly-redos, showing how to just limit the length of the input
|
2023-05-23 09:25:15 +02:00 |
|