jorgectf
|
b6bdcd0eb8
|
Delete redundant exists()
|
2021-12-19 18:57:22 +01:00 |
|
jorgectf
|
98c8503ebd
|
Fix test mismatch
|
2021-12-19 18:35:53 +01:00 |
|
jorgectf
|
f82ed8573e
|
Model python_jwt.process_jwt
|
2021-12-19 18:32:14 +01:00 |
|
Chris Gavin
|
8fabbd697e
|
Merge pull request #7422 from github/todo-comment-kind
Add `kind` metadata to example query.
|
2021-12-16 16:36:15 +00:00 |
|
Chris Smowton
|
e3b2eed2d2
|
Merge pull request #7423 from github/atorralba/log4j-CVE-2021-45046
Java: Cover CVE-2021-45046 in the Log4jJndiInjection query
|
2021-12-16 16:00:45 +00:00 |
|
Tom Hvitved
|
579b58b8fa
|
Merge pull request #7402 from github/workflow/coverage/update
Update CSV framework coverage reports
|
2021-12-16 15:42:10 +01:00 |
|
Chris Gavin
|
4a1e2ed408
|
Add a severity and select the correct number of columns.
|
2021-12-16 14:02:36 +00:00 |
|
Tom Hvitved
|
e9ef53c31b
|
Merge pull request #7390 from hvitved/ruby/deprecate-pattern-classes
Ruby: Deprecate `Pattern` classes
|
2021-12-16 14:36:13 +01:00 |
|
Tony Torralba
|
7d6cba77a0
|
Add tests
|
2021-12-16 13:44:01 +01:00 |
|
Tony Torralba
|
2e0ca6ce2b
|
Add stubs
|
2021-12-16 13:44:01 +01:00 |
|
Tony Torralba
|
7d70b77141
|
Add new sinks and taint steps
|
2021-12-16 13:43:58 +01:00 |
|
Chris Gavin
|
407c265daf
|
Add kind metadata to example query.
|
2021-12-16 12:12:36 +00:00 |
|
Michael Nebel
|
95d175e9e0
|
Merge pull request #7406 from michaelnebel/csharp-system-threading-csv
C#: Convert more flow summaries to CSV format.
|
2021-12-16 12:56:44 +01:00 |
|
Michael Nebel
|
d777ba8a25
|
C#: Cleanup private imports in LibraryTypeDataFlow.
|
2021-12-16 11:24:24 +01:00 |
|
Michael Nebel
|
a26403b359
|
Convert System.Tuple and friends flow to CSV format.
|
2021-12-16 11:20:04 +01:00 |
|
Michael Nebel
|
348e3b74f3
|
C#: Convert System.Text.Encoding flow to CSV format.
|
2021-12-16 10:03:12 +01:00 |
|
CodeQL CI
|
f274f06d9b
|
Merge pull request #7409 from asgerf/js/track-functions-with-methods
Approved by erik-krogh
|
2021-12-16 09:01:42 +00:00 |
|
CodeQL CI
|
acbf7913b2
|
Merge pull request #7408 from asgerf/js/trusted-types-sinks
Approved by esbena
|
2021-12-16 08:59:51 +00:00 |
|
Michael Nebel
|
a5c055581e
|
C#: Convert System.Runtime.CompilerServices.ConfiguredTaskAwaitable<>.ConfiguredTaskAwaiter flow to CSV format.
|
2021-12-16 09:36:39 +01:00 |
|
Michael Nebel
|
ddb7d722bc
|
C#: Convert System.Runtime.CompilerServices.TaskAwaiter<> flow to CSV format.
|
2021-12-16 09:36:39 +01:00 |
|
Michael Nebel
|
bdd44c1c46
|
C#: Convert System.Runtime.CompilerServices.ConfiguredTaskAwaitable flow to CSV format.
|
2021-12-16 09:36:39 +01:00 |
|
Michael Nebel
|
034d45ddc0
|
C#: Convert System.Threading.Tasks.TaskFactory flow to CSV format.
|
2021-12-16 09:36:39 +01:00 |
|
Michael Nebel
|
440976fe63
|
C#: Convert System.Threading.Tasks.Task<> flow to CSV format.
|
2021-12-16 09:36:39 +01:00 |
|
Michael Nebel
|
cde98c7799
|
C#: Convert System.Threading.Tasks.Task flow to CSV format.
|
2021-12-16 09:36:39 +01:00 |
|
Michael Nebel
|
90d7b94b8a
|
Merge pull request #7413 from hvitved/csharp/fix-test
C#: Fix broken `FlowSummariesFiltered` test
|
2021-12-16 09:31:33 +01:00 |
|
github-actions[bot]
|
18489c0ded
|
Add changed framework coverage reports
|
2021-12-16 00:09:34 +00:00 |
|
Tom Hvitved
|
4ccf9bf67c
|
Address review comments
|
2021-12-15 19:57:27 +01:00 |
|
Tom Hvitved
|
8f1b2b3bb5
|
C#: Fix broken FlowSummariesFiltered test
|
2021-12-15 18:32:25 +01:00 |
|
Arthur Baars
|
b53e3499cb
|
Merge pull request #7249 from ShockwaveNN/patch-1
Fix ruby incorrect version in documentation
|
2021-12-15 18:32:24 +01:00 |
|
Tom Hvitved
|
3bc6247ad8
|
Merge pull request #7378 from hvitved/ruby/module-infinite-loop
Ruby: Prevent infinite recursion in module resolution library
|
2021-12-15 16:27:36 +01:00 |
|
Tom Hvitved
|
c6696adfde
|
Ruby: Add test case that would make old module resolution library diverge
|
2021-12-15 15:18:42 +01:00 |
|
Tom Hvitved
|
2187994f5c
|
Ruby: Prevent infinite recursion in module resolution library
|
2021-12-15 15:15:19 +01:00 |
|
Arthur Baars
|
7ddfc00655
|
Merge branch 'main' into patch-1
|
2021-12-15 14:52:35 +01:00 |
|
Tony Torralba
|
7e644d8d7b
|
Merge pull request #6098 from atorralba/atorralba/entrypoint-field-steps
Java: Preserve taint on field-read-steps on entrypoint types
|
2021-12-15 14:51:38 +01:00 |
|
Tony Torralba
|
c1e4c05aa2
|
Update change note to new format
|
2021-12-15 13:08:34 +01:00 |
|
Tony Torralba
|
e2022f467c
|
Update java/ql/lib/semmle/code/java/dataflow/internal/TaintTrackingUtil.qll
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2021-12-15 13:00:16 +01:00 |
|
Tony Torralba
|
a3b25f0eb5
|
Don't consider subtypes of fields
|
2021-12-15 13:00:16 +01:00 |
|
Tony Torralba
|
47002a3bd7
|
Fix test
|
2021-12-15 13:00:16 +01:00 |
|
Tony Torralba
|
1426c5b406
|
Consider parameterized types
|
2021-12-15 13:00:16 +01:00 |
|
Tony Torralba
|
7ce9b04941
|
Add change note
|
2021-12-15 13:00:15 +01:00 |
|
Tony Torralba
|
5e80044f11
|
Preserve taint on field-read-steps on entrypoint types
|
2021-12-15 13:00:15 +01:00 |
|
Asger Feldthaus
|
e64a6dc12a
|
JS: Add qldoc
|
2021-12-15 12:47:23 +01:00 |
|
Asger Feldthaus
|
43ec721a87
|
JS: Add link to MDN docs for trusted types
|
2021-12-15 11:52:58 +01:00 |
|
Geoffrey White
|
9363d64166
|
Merge pull request #7395 from MathiasVP/fix-fp-in-pointless-self-comparison
C++: Fix FP in `cpp/comparison-of-identical-expressions`
|
2021-12-15 10:47:57 +00:00 |
|
Mathias Vorreiter Pedersen
|
65c301c39f
|
Update cpp/ql/test/query-tests/Likely Bugs/Arithmetic/BadAdditionOverflowCheck/templates.cpp
Co-authored-by: Geoffrey White <40627776+geoffw0@users.noreply.github.com>
|
2021-12-15 09:22:41 +00:00 |
|
Michael Nebel
|
0e7fdbeeab
|
Merge pull request #7384 from michaelnebel/csharp-mad-xml
C#: Convert XML related flow summaries to CSV and fix flow summaries test cases.
|
2021-12-15 09:51:20 +01:00 |
|
Harry Maclean
|
062f7fe390
|
Merge pull request #7340 from github/hmac/private-methods
Ruby: handle private module methods
|
2021-12-15 21:07:49 +13:00 |
|
Harry Maclean
|
a32711245f
|
Ruby: Further speed up private method modelling
|
2021-12-15 17:38:52 +13:00 |
|
Tom Hvitved
|
15caaa7ad6
|
Merge pull request #7377 from hvitved/csharp/overriable-class
C#: Introduce class `Overridable`
|
2021-12-14 20:01:12 +01:00 |
|
Mathias Vorreiter Pedersen
|
310353060e
|
C++: Also fix the FP in 'cpp/comparison-canceling-subexpr'.
|
2021-12-14 17:08:10 +00:00 |
|