erik-krogh
|
b471a401cc
|
update {rb/js/java}/unused-parameter to match python
|
2022-08-22 21:41:45 +02:00 |
|
Tom Hvitved
|
08a5b5dc73
|
Merge pull request #10089 from hvitved/ruby/local-source-nodes
Ruby: Reduce size of `isLocalSourceNode`
|
2022-08-18 12:02:35 +02:00 |
|
Harry Maclean
|
70ec70940a
|
Merge pull request #8142 from github/hmac/incomplete-multi-char-sanitization
|
2022-08-18 10:02:39 +12:00 |
|
Tom Hvitved
|
ed2ec1acc0
|
Ruby: Reduce size of isLocalSourceNode
|
2022-08-17 17:19:30 +02:00 |
|
Alex Ford
|
d4d6657cb7
|
Merge pull request #10008 from alexrford/rb/log-injection
Ruby: Add `rb/log-injection` query
|
2022-08-17 15:01:22 +01:00 |
|
Harry Maclean
|
f1a546c4d6
|
Rename IncompleteMultiCharacterSanitization[Query]
|
2022-08-17 16:03:49 +12:00 |
|
Harry Maclean
|
f2384a6a8f
|
Ruby: Share more code with JS
|
2022-08-17 16:03:49 +12:00 |
|
Harry Maclean
|
025e34d8e1
|
Ruby: Simplify imports
|
2022-08-17 16:03:48 +12:00 |
|
Harry Maclean
|
ab6287aebd
|
Ruby: Fix import
|
2022-08-17 16:03:48 +12:00 |
|
Harry Maclean
|
c234bd94d1
|
Ruby: IncompleteMultiCharacterSanitization Query
This query is similar to IncompleteSanitization but for multi-character
sequences.
|
2022-08-17 16:02:48 +12:00 |
|
Erik Krogh Kristensen
|
f106e064fa
|
Merge pull request #9422 from erik-krogh/refacReDoS
Refactorizations of the ReDoS libraries
|
2022-08-16 09:32:08 +02:00 |
|
Erik Krogh Kristensen
|
0adb588fe8
|
Merge pull request #9712 from erik-krogh/badRange
JS/RB/PY/Java: add suspicious range query
|
2022-08-15 13:55:44 +02:00 |
|
Alex Ford
|
00e290e1f1
|
Ruby: document rb/log-injection
|
2022-08-10 16:17:18 +01:00 |
|
Alex Ford
|
c31995764b
|
Ruby: add rb/log-inection query
|
2022-08-10 16:16:54 +01:00 |
|
Erik Krogh Kristensen
|
49276b1f38
|
Merge branch 'main' into refacReDoS
|
2022-08-09 16:18:46 +02:00 |
|
Erik Krogh Kristensen
|
0abbd50ca1
|
apply changes based on docs review
|
2022-08-09 13:51:40 +02:00 |
|
Erik Krogh Kristensen
|
a4262f8d91
|
add some more references to the overly-large-range qhelp
|
2022-07-13 11:20:24 +02:00 |
|
Erik Krogh Kristensen
|
c4f44bb67f
|
sync files
|
2022-07-13 10:01:26 +02:00 |
|
Erik Krogh Kristensen
|
220ff3cb2e
|
convert tabs to spaces in qhelp
|
2022-07-12 16:02:50 +02:00 |
|
Erik Krogh Kristensen
|
ff25451699
|
rename query to overly-large-range, and rewrite the @description
|
2022-07-12 16:02:46 +02:00 |
|
Erik Krogh Kristensen
|
2e295e4a04
|
filter out potential misparses from rb/suspicious-regexp-range
|
2022-06-29 13:16:28 +02:00 |
|
Erik Krogh Kristensen
|
a343ceaf8b
|
add suspicious-regexp-range query
|
2022-06-28 09:49:27 +02:00 |
|
Erik Krogh Kristensen
|
13482fc97b
|
rename ReDoSUtil to NfaUtils, and rename the "performance" folder to "regexp"
|
2022-06-23 14:36:25 +02:00 |
|
Erik Krogh Kristensen
|
3be4a86acd
|
make ReDoSPruning into a parameterized module
|
2022-06-23 14:36:25 +02:00 |
|
Erik Krogh Kristensen
|
dc06e9df02
|
move predicates that depend on isReDoSCandidate into a ReDoSPruning module
|
2022-06-23 14:36:24 +02:00 |
|
Anders Schack-Mulligen
|
1b13790a36
|
Ruby: Deprecate and replace BarrierGuard class.
|
2022-06-20 15:46:38 +02:00 |
|
Alex Ford
|
8d195e3188
|
Merge pull request #9157 from alexrford/crypto-op-block-mode
Ruby/Python: Add a `BlockMode` concept for `CryptographicOperations`
|
2022-06-13 21:32:36 +02:00 |
|
Nick Rolfe
|
385e442f7f
|
Ruby: fix spelling errors
|
2022-05-25 16:38:48 +01:00 |
|
Alex Ford
|
4752c45fe5
|
ruby: update rb/weak-cryptographic-algorithm to specify the block mode if appropriate
|
2022-05-13 16:32:30 +01:00 |
|
yoff
|
6c3e2db7fd
|
Merge branch 'main' into python/simple-csrf
|
2022-05-10 10:55:28 +02:00 |
|
Harry Maclean
|
ba1d43dd42
|
Merge pull request #8658 from hmac/hmac/insecure-download
Ruby: Add InsecureDownload query
|
2022-04-28 11:07:35 +12:00 |
|
Harry Maclean
|
f4453f4da2
|
Merge pull request #8573 from hmac/hmac/missing-regexp-anchor
Ruby: Add MissingRegExpAnchor query
|
2022-04-28 11:06:33 +12:00 |
|
Erik Krogh Kristensen
|
e1c7d369be
|
Merge pull request #8796 from erik-krogh/redundantImport
Remove redundant imports
|
2022-04-27 12:39:51 +02:00 |
|
Harry Maclean
|
f35379bf8c
|
Ruby: Add change note for rb/insecure-download
|
2022-04-27 12:47:09 +12:00 |
|
Harry Maclean
|
bb3fb0325b
|
Ruby: Add InsecureDownload query
This query finds cases where a potentially unsafe file is downloaded
over an unsecured connection.
|
2022-04-27 12:47:09 +12:00 |
|
Harry Maclean
|
af2965c2a0
|
Explain anchors in MissingRegExpAnchor qlhelp
|
2022-04-27 10:12:33 +12:00 |
|
Harry Maclean
|
6f9dc5eb7e
|
Ruby: Update import for file move
|
2022-04-27 10:12:33 +12:00 |
|
Harry Maclean
|
2feb4a48be
|
Ruby: Add hasMisleadingAnchorPrecedence to MissingRegExpAnchor
|
2022-04-27 10:12:33 +12:00 |
|
Harry Maclean
|
e3c3c00c68
|
Ruby: Add MissingRegExpAnchor query
|
2022-04-27 10:12:33 +12:00 |
|
Nick Rolfe
|
649d7dd022
|
Merge pull request #8607 from github/nickrolfe/incomplete_sanitization
Ruby: port of `js/incomplete-sanitization`
|
2022-04-26 17:10:24 +01:00 |
|
Erik Krogh Kristensen
|
ff73dbc35c
|
delete redundant imports
|
2022-04-22 12:55:28 +02:00 |
|
Erik Krogh Kristensen
|
a737350f27
|
RB: dont import the PathGraph module from Query.qll files
|
2022-04-22 11:46:06 +02:00 |
|
Nick Rolfe
|
9b2a98326c
|
Ruby: update use of PostUpdateNode now that it's public
|
2022-04-20 12:08:41 +01:00 |
|
Nick Rolfe
|
9b6e610e24
|
Merge remote-tracking branch 'origin/main' into nickrolfe/incomplete_sanitization
|
2022-04-20 12:05:22 +01:00 |
|
Nick Rolfe
|
08f6fbbe10
|
Ruby: make comment about backslash escaping clearer
|
2022-04-19 14:05:17 +01:00 |
|
Nick Rolfe
|
76c6a521fd
|
Ruby: add clarifying comment
|
2022-04-19 13:10:57 +01:00 |
|
Nick Rolfe
|
76587c4144
|
Ruby: fix capitalisation of String in qhelp
|
2022-04-19 11:42:31 +01:00 |
|
Nick Rolfe
|
ac805f0cdc
|
Ruby: simplify predicate by using DataFlow::CallNode
|
2022-04-19 11:27:33 +01:00 |
|
Nick Rolfe
|
ca4dc0583d
|
Ruby: fix comment typos
|
2022-04-19 11:15:34 +01:00 |
|
Harry Maclean
|
c3f1fba985
|
Merge pull request #8598 from hmac/hmac/insecure-dep-resolution
Ruby: Add rb/insecure-dependency query
|
2022-04-14 02:09:44 +02:00 |
|