Tom Hvitved
|
46631d6eaf
|
Merge pull request #10931 from hvitved/ruby/fix-flow-into-phis
Ruby: Fix flow steps into phi nodes
|
2022-11-02 21:07:06 +01:00 |
|
Tom Hvitved
|
f603d96f48
|
Merge pull request #11074 from github/revert-10576-ssa/consistency-queries
Revert "SSA: Turn consistency predicates into `query` predicates"
|
2022-11-02 11:29:42 +01:00 |
|
Tom Hvitved
|
2d5b9c12a6
|
Ruby: Avoid calls to deprecated SSA predicates
|
2022-11-02 09:37:28 +01:00 |
|
Tom Hvitved
|
780ea72b3b
|
Revert "SSA: Turn consistency predicates into query predicates"
|
2022-11-02 09:11:45 +01:00 |
|
Tom Hvitved
|
ee9163aa40
|
Ruby: Fix flow steps into phi nodes
- Add missing flow from post-update nodes into phi nodes.
- Prevent flow from reads into phi nodes when use-use flow is prohibited.
|
2022-11-01 16:33:06 +01:00 |
|
Tom Hvitved
|
a191edfbd5
|
Ruby: Add data flow tests that illustrate problems with flow into SSA phi nodes
|
2022-11-01 16:32:46 +01:00 |
|
Tom Hvitved
|
e8f9429b92
|
Merge pull request #10917 from hvitved/ruby/singleton-call-sensitivity
Ruby: Call-context sensitivity for singleton method calls
|
2022-11-01 14:13:26 +01:00 |
|
Arthur Baars
|
aba87a139d
|
Merge pull request #10668 from aibaars/ruby-deps
Ruby: update dependencies
|
2022-11-01 13:55:42 +01:00 |
|
Tom Hvitved
|
4edef874d6
|
SSA: Turn consistency predicates into query predicates
|
2022-11-01 10:01:56 +01:00 |
|
erik-krogh
|
84a7fddd95
|
remove explicit versions in lock files, as the dependencies are all installed locally
|
2022-11-01 09:09:26 +01:00 |
|
Harry Maclean
|
3f403f0f87
|
Merge pull request #10700 from hmac/activesupport
Ruby: Model some ActiveSupport methods
|
2022-10-31 11:50:44 +13:00 |
|
Rasmus Wriedt Larsen
|
8628ff5e52
|
Merge pull request #10999 from RasmusWL/inline-fail-tag
InlineExpectationsTest: Fail if missing `getARelevantTag`
|
2022-10-28 10:35:49 +02:00 |
|
Erik Krogh Kristensen
|
93fb2930c8
|
Merge pull request #10968 from erik-krogh/fixRbCode
RB: fix rb/code-injection
|
2022-10-28 09:14:14 +02:00 |
|
Harry Maclean
|
368ce69198
|
Fix qldoc formatting
|
2022-10-28 11:31:55 +13:00 |
|
Harry Maclean
|
9df8edcb1c
|
Ruby: fix formatting
|
2022-10-28 11:31:55 +13:00 |
|
Harry Maclean
|
cd34686967
|
Ruby: Document flow summary for Hash#extract!
|
2022-10-28 11:31:55 +13:00 |
|
Harry Maclean
|
ca7b48c3d5
|
Add change note
|
2022-10-28 11:31:55 +13:00 |
|
Harry Maclean
|
5e781f24b6
|
Ruby: Remove duplicate test
This is already tested in hash-flow.
|
2022-10-28 11:31:55 +13:00 |
|
Harry Maclean
|
4ec527a9ea
|
Ruby: Explain difference between flow tests
The type-tracking flow tests document the difference in sensitivity
between type-tracking and dataflow, so failures in that test are
expected.
|
2022-10-28 11:31:55 +13:00 |
|
Harry Maclean
|
6e8446b6ae
|
Fix tests
|
2022-10-28 11:31:55 +13:00 |
|
Harry Maclean
|
ef260db76e
|
Fix singleton set literal
|
2022-10-28 11:31:55 +13:00 |
|
Harry Maclean
|
71d703f2a5
|
Ruby: Add ActiveSupport extensions
|
2022-10-28 11:31:55 +13:00 |
|
Harry Maclean
|
cb37a0e835
|
Ruby: Add summaries for Hash#deep_merge(!)
|
2022-10-28 11:31:55 +13:00 |
|
Harry Maclean
|
3dea1d6a60
|
Ruby: Add flow summary for Hash#except!
|
2022-10-28 11:31:55 +13:00 |
|
Harry Maclean
|
0454642220
|
Ruby: Model deep_dup and presence
|
2022-10-28 11:31:55 +13:00 |
|
Harry Maclean
|
9f260853ac
|
Ruby: Model more ActiveSupport string extensions
|
2022-10-28 11:31:55 +13:00 |
|
Harry Maclean
|
b389d50943
|
Ruby: Identify safe_constantize
|
2022-10-28 11:31:54 +13:00 |
|
Rasmus Wriedt Larsen
|
adf109b624
|
Merge branch 'main' into inline-fail-tag
|
2022-10-27 13:42:32 +02:00 |
|
Rasmus Wriedt Larsen
|
6d43db43dd
|
Ruby: Fix tag missing from getARelevantTag
|
2022-10-27 09:12:06 +02:00 |
|
Rasmus Wriedt Larsen
|
fc7eb5b4fc
|
InlineExpectationsTest: sync
|
2022-10-27 09:02:28 +02:00 |
|
Rasmus Wriedt Larsen
|
5e9897d150
|
InlineExpectationsTest: sync
|
2022-10-26 18:21:13 +02:00 |
|
thiggy1342
|
9c1fbfd330
|
Merge branch 'main' into expand-ruby-ssrf-sinks-faraday-connection-new
|
2022-10-25 13:09:17 -04:00 |
|
thiggy1342
|
3659eaa780
|
add markdown file extension
|
2022-10-25 10:13:19 -04:00 |
|
erik-krogh
|
e8dce25cc2
|
fix rb/code-injection
|
2022-10-25 14:44:23 +02:00 |
|
Erik Krogh Kristensen
|
ef5132b0ae
|
Merge pull request #10883 from erik-krogh/codeSink
RB: don't flag code-injection for dynamic loading where an attacker only controls a substring
|
2022-10-24 18:59:36 +02:00 |
|
thiggy1342
|
952ad6ea46
|
Merge branch 'main' into expand-ruby-ssrf-sinks-faraday-connection-new
|
2022-10-24 09:52:24 -04:00 |
|
Erik Krogh Kristensen
|
5ff98cd80e
|
Merge pull request #10888 from erik-krogh/glob
Ruby: add model for Dir.glob and other Dir methods
|
2022-10-24 14:17:37 +02:00 |
|
Asger F
|
bcfe4ece6f
|
Merge pull request #10918 from asgerf/rb/constant-compound-assignment
Ruby: handle compound constant-assignment
|
2022-10-24 14:07:28 +02:00 |
|
Asger F
|
cac2e2e2e4
|
Merge pull request #10928 from asgerf/rb/assumed-global-const
Ruby: assume some global constants are defined
|
2022-10-24 14:06:34 +02:00 |
|
Asger F
|
0ffb0f6d4d
|
Ruby: constant lookup is unaffected by blocks
|
2022-10-24 13:07:21 +02:00 |
|
erik-krogh
|
07d90b34df
|
use instanceof in DirPathAccess
|
2022-10-24 12:05:26 +02:00 |
|
Erik Krogh Kristensen
|
669b0c35fe
|
fix qldoc
Co-authored-by: Nick Rolfe <nickrolfe@github.com>
|
2022-10-24 12:05:26 +02:00 |
|
erik-krogh
|
85cd7f9121
|
add model for Dir.glob and other Dir methods
|
2022-10-24 12:05:26 +02:00 |
|
Arthur Baars
|
b3855b089a
|
Ruby: some more tests
|
2022-10-22 14:15:29 +02:00 |
|
Arthur Baars
|
ccaa12998d
|
Ruby: desugar compound constant-assignments
|
2022-10-22 01:11:35 +02:00 |
|
Nick Rolfe
|
9fb436e22b
|
Ruby: add change note for localTaintStep fix
|
2022-10-21 16:33:29 +01:00 |
|
Nick Rolfe
|
269c27757d
|
Ruby: include value-preserving flow in localTaintStep
|
2022-10-21 16:17:11 +01:00 |
|
Nick Rolfe
|
5319216c18
|
Ruby: add test of TaintTracking::localFlowStep
|
2022-10-21 16:04:04 +01:00 |
|
Asger F
|
84ae17dcbb
|
Ruby: ensure Object is a transitive superclass
|
2022-10-21 15:18:59 +02:00 |
|
Arthur Baars
|
a56ed88db2
|
Merge pull request #10920 from github/post-release-prep/codeql-cli-2.11.2
Post-release preparation for codeql-cli-2.11.2
|
2022-10-21 11:58:12 +02:00 |
|