Erik Krogh Kristensen
|
b18f51806c
|
regain the lost property presence result
|
2020-09-04 10:30:38 +02:00 |
|
Erik Krogh Kristensen
|
6fccf5aa70
|
use isLikelyIntentionalHtmlSink in the sink instead of in the where clause
|
2020-09-04 09:26:03 +02:00 |
|
CodeQL CI
|
58f51899c9
|
Merge pull request #4173 from erik-krogh/targetBlankFP
Approved by esbena
|
2020-09-04 08:21:22 +01:00 |
|
Tom Hvitved
|
7f18c3377e
|
Merge pull request #4017 from hvitved/csharp/unqualify-trap-ids3
C#: Remove assembly prefixes from TRAP labels
|
2020-09-04 09:20:39 +02:00 |
|
Mathias Vorreiter Pedersen
|
b7774b2a82
|
Merge pull request #4201 from geoffw0/insert
C++: Model iterator versions of string and vector methods
|
2020-09-03 21:45:36 +02:00 |
|
CodeQL CI
|
f180497554
|
Merge pull request #4192 from max-schaefer/js/ssa__implicitinit
Approved by asgerf
|
2020-09-03 16:46:56 +01:00 |
|
CodeQL CI
|
c8ffde20f4
|
Merge pull request #4195 from RasmusWL/python-taint-default-sanitizer
Approved by tausbn
|
2020-09-03 13:55:32 +01:00 |
|
Erik Krogh Kristensen
|
ed54fdcb06
|
Merge pull request #4118 from dellalibera/js/ldap
[javascript] CodeQL to detect LDAP Injection
|
2020-09-03 14:50:03 +02:00 |
|
Erik Krogh Kristensen
|
d56ea22018
|
Merge pull request #4200 from erik-krogh/typeaheadInconsistencyComment
JS: adjust comment about inconsistency for XSS in typeahead
|
2020-09-03 13:56:40 +02:00 |
|
Erik Krogh Kristensen
|
d946a61d6e
|
update expected output
|
2020-09-03 13:32:54 +02:00 |
|
Nick Rolfe
|
b8ae87470d
|
Merge pull request #4182 from github/igfoo/cfg
C++: Remove some remnants of the extractor CFG
|
2020-09-03 12:22:04 +01:00 |
|
Geoffrey White
|
50d9a85143
|
C++: Update change note.
|
2020-09-03 10:52:27 +01:00 |
|
Geoffrey White
|
d4cbb25e09
|
C++: Model std::string constructors and container constructors that use iterators.
|
2020-09-03 10:52:27 +01:00 |
|
Geoffrey White
|
1ac0aa169d
|
C++: Add a few more test cases.
|
2020-09-03 10:52:26 +01:00 |
|
Geoffrey White
|
1ad404c605
|
C++: Extend model to include std::forward_list::insert_after.
|
2020-09-03 10:52:26 +01:00 |
|
Geoffrey White
|
fcacb22cad
|
C++: Use [] in std::string begin model.
|
2020-09-03 10:52:26 +01:00 |
|
Geoffrey White
|
95ca4b674d
|
C++: Add model for std::vector::insert.
|
2020-09-03 10:52:25 +01:00 |
|
Geoffrey White
|
f61c7ffc1a
|
C++: Add support for iterator parameters to std::vector::assign.
|
2020-09-03 10:52:25 +01:00 |
|
Geoffrey White
|
8e9faac363
|
C++: Add support for std::vector begin and end.
|
2020-09-03 10:52:24 +01:00 |
|
Geoffrey White
|
4d47eaa08d
|
C++: Add support for iterator parameters to std::string::assign.
|
2020-09-03 10:52:24 +01:00 |
|
Geoffrey White
|
98f84646d6
|
C++: Result changes due to iterators PR, which adds support for std::string begin and end, and iterator parameters to std::string::insert and some similar functions.
|
2020-09-03 10:52:24 +01:00 |
|
Geoffrey White
|
7917dff843
|
C++: Add test cases for std::string and std::vector using iterator methods.
|
2020-09-03 10:52:23 +01:00 |
|
Geoffrey White
|
fcdbe0f512
|
C++: Add a const conversion constructor to std::iterator in the tests.
|
2020-09-03 10:52:23 +01:00 |
|
CodeQL CI
|
aa4237c27c
|
Merge pull request #4191 from erik-krogh/v8Syntax
Approved by esbena
|
2020-09-03 09:57:00 +01:00 |
|
Erik Krogh Kristensen
|
3952553953
|
adjust comment about inconsistency for XSS in typeahead
|
2020-09-03 10:50:40 +02:00 |
|
Alessio Della Libera
|
116e7d006d
|
Update javascript/ql/src/experimental/Security/CWE-090/LdapInjection.qhelp
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2020-09-03 10:32:18 +02:00 |
|
Alessio Della Libera
|
bfae0ef5d5
|
Update javascript/ql/src/experimental/Security/CWE-090/LdapInjection.qhelp
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2020-09-03 10:32:08 +02:00 |
|
CodeQL CI
|
2ba84be565
|
Merge pull request #4185 from erik-krogh/unusedArrDestruct
Approved by esbena
|
2020-09-03 09:18:15 +01:00 |
|
Erik Krogh Kristensen
|
4fdd2cd794
|
add change note
|
2020-09-03 10:06:52 +02:00 |
|
Erik Krogh Kristensen
|
1f9749fbfe
|
revert mailto: change in TargetBlank.ql
|
2020-09-03 09:39:01 +02:00 |
|
Erik Krogh Kristensen
|
d7a96d685a
|
simplify implementation of getDelimiterMatchingRegexp
|
2020-09-03 09:37:43 +02:00 |
|
Erik Krogh Kristensen
|
87d39db95f
|
add change note
|
2020-09-03 08:58:33 +02:00 |
|
Erik Krogh Kristensen
|
ec21236bba
|
update docstring for isNonLastDestructedArrayElement
Co-authored-by: Esben Sparre Andreasen <esbena@github.com>
|
2020-09-03 08:51:10 +02:00 |
|
Erik Krogh Kristensen
|
fb3148a7a8
|
autoformat
|
2020-09-03 08:17:08 +02:00 |
|
Arthur Baars
|
00668b536a
|
Merge pull request #4188 from aibaars/csharp-buildless
C#: autobuild: fix buildless mode for CodeQL
|
2020-09-02 21:04:39 +02:00 |
|
Ian Lynagh
|
8c7431c4ae
|
C++: Put {true,false}cond_base back as deprecated predicates for now
|
2020-09-02 19:10:36 +01:00 |
|
Ian Lynagh
|
c980ccf7c5
|
C++: Add an upgrade script
|
2020-09-02 19:05:05 +01:00 |
|
Ian Lynagh
|
8ce1edbed3
|
C++: Update stats now CFG tables have been removed
|
2020-09-02 19:05:05 +01:00 |
|
Arthur Baars
|
babe69d6e9
|
Update unit tests
|
2020-09-02 17:59:56 +02:00 |
|
Rasmus Wriedt Larsen
|
bf34b07605
|
Python: Add a few taint tests for default sanitizer
specifically the ones removes from dataflow tests in https://github.com/yoff/codeql/pull/1
|
2020-09-02 16:56:05 +02:00 |
|
Taus
|
8e86d56bce
|
Merge pull request #4189 from RasmusWL/python-experimental-file-structure
Python: Move files in experimental dirs to be consistent
|
2020-09-02 16:34:35 +02:00 |
|
Arthur Baars
|
90f013d74f
|
Merge pull request #4176 from aibaars/missing-qhelp
Add missing QHelp files
|
2020-09-02 16:12:42 +02:00 |
|
Asger F
|
2c0e9f0c86
|
Merge pull request #4186 from github/rc/1.25
Mergeback: 1.25 -> main
|
2020-09-02 15:12:25 +01:00 |
|
Rasmus Wriedt Larsen
|
8aab0c8be7
|
Python: Fix .qlref for experimental security tests
|
2020-09-02 15:35:50 +02:00 |
|
Max Schaefer
|
cd64ce7b1a
|
JavaScript: Add utility predicate SSA::implicitInit.
|
2020-09-02 14:34:52 +01:00 |
|
CodeQL CI
|
c017308505
|
Merge pull request #4134 from erik-krogh/genCalls
Approved by asgerf
|
2020-09-02 14:23:39 +01:00 |
|
Alessio Della Libera
|
785f335ab8
|
Update javascript/ql/src/experimental/Security/CWE-090/LdapInjectionCustomizations.qll
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2020-09-02 15:22:33 +02:00 |
|
Alessio Della Libera
|
548cb65a64
|
Update javascript/ql/src/experimental/Security/CWE-090/LdapInjectionCustomizations.qll
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2020-09-02 15:22:23 +02:00 |
|
Alessio Della Libera
|
26046a4847
|
Update javascript/ql/src/experimental/Security/CWE-090/LdapInjectionCustomizations.qll
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2020-09-02 15:22:07 +02:00 |
|
Alessio Della Libera
|
6ad88bf93f
|
Update javascript/ql/src/experimental/Security/CWE-090/LdapInjection.ql
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2020-09-02 15:21:55 +02:00 |
|