Asger F
|
cc57cb8af5
|
Merge branch 'main' into post-release-prep/codeql-cli-2.10.0
|
2022-06-27 20:37:25 +02:00 |
|
Rasmus Wriedt Larsen
|
9e154ff4bd
|
Merge branch 'main' into python/port-tarslip
|
2022-06-27 14:36:15 +02:00 |
|
Erik Krogh Kristensen
|
9bc12ed8fd
|
sync review changes to other languages
|
2022-06-24 13:12:15 +02:00 |
|
Erik Krogh Kristensen
|
28ac47689f
|
changes based on reviews
|
2022-06-24 13:11:46 +02:00 |
|
github-actions[bot]
|
d506f448ef
|
Post-release preparation for codeql-cli-2.10.0
|
2022-06-24 07:36:33 +00:00 |
|
Anders Schack-Mulligen
|
dc517a758e
|
Autoformat
|
2022-06-23 14:44:40 +02:00 |
|
Erik Krogh Kristensen
|
724721c5c8
|
fix typo
|
2022-06-23 14:36:25 +02:00 |
|
Erik Krogh Kristensen
|
22871138c6
|
simplify the recursion between TTrace and isReachableFromStartTuple
similar to the fix made by Shack in `ExponentialBackTracking.qll`
|
2022-06-23 14:36:25 +02:00 |
|
Erik Krogh Kristensen
|
be37763125
|
improve performance of process() by pruning accept states early
|
2022-06-23 14:36:25 +02:00 |
|
Erik Krogh Kristensen
|
bf20b7dfc5
|
add change note for the ReDoS renamings
|
2022-06-23 14:36:25 +02:00 |
|
Erik Krogh Kristensen
|
3bea7df45d
|
add deprecated aliases in the old locations, and use the Query.qll pattern for js/polynomial-redos
|
2022-06-23 14:36:25 +02:00 |
|
Erik Krogh Kristensen
|
13482fc97b
|
rename ReDoSUtil to NfaUtils, and rename the "performance" folder to "regexp"
|
2022-06-23 14:36:25 +02:00 |
|
Erik Krogh Kristensen
|
6b0df9bdfb
|
refactor the concretize algorithm
|
2022-06-23 14:36:25 +02:00 |
|
Erik Krogh Kristensen
|
dbeae9aefb
|
make a parameterized module out of the RegexpMatching implementation
|
2022-06-23 14:36:25 +02:00 |
|
Erik Krogh Kristensen
|
7fb3d81d2f
|
add further normalization of char classses
|
2022-06-23 14:36:25 +02:00 |
|
Erik Krogh Kristensen
|
3be4a86acd
|
make ReDoSPruning into a parameterized module
|
2022-06-23 14:36:25 +02:00 |
|
Erik Krogh Kristensen
|
dc06e9df02
|
move predicates that depend on isReDoSCandidate into a ReDoSPruning module
|
2022-06-23 14:36:24 +02:00 |
|
Anders Schack-Mulligen
|
4a317a25d3
|
Dataflow: Sync.
|
2022-06-23 14:34:52 +02:00 |
|
Asger F
|
d94010c244
|
Grammar: report -> reports
|
2022-06-23 14:17:52 +02:00 |
|
github-actions[bot]
|
a74051c658
|
Release preparation for version 2.10.0
|
2022-06-23 11:17:46 +00:00 |
|
Rasmus Wriedt Larsen
|
3248f7b423
|
Merge pull request #9649 from RasmusWL/certificate-modeling
Python/JS/Ruby: Ignore common words (like certain) as sensitive data source
|
2022-06-23 12:04:58 +02:00 |
|
Rasmus Wriedt Larsen
|
876ba71d9b
|
Python/JS/Ruby: Add change-note
|
2022-06-22 11:14:05 +02:00 |
|
Rasmus Wriedt Larsen
|
4be375521f
|
Python: Handle _ in sensitive-data-sources
|
2022-06-22 11:05:14 +02:00 |
|
Rasmus Wriedt Larsen
|
4a844312f4
|
Python: _ in var name not handled by sensitive-data-sources
|
2022-06-22 11:05:14 +02:00 |
|
Rasmus Wriedt Larsen
|
5dc2bb717a
|
Python: ignore common words (certain/concert) as sensitive source
|
2022-06-22 11:05:05 +02:00 |
|
Anders Schack-Mulligen
|
df6d68b215
|
Merge pull request #9618 from aschackmull/dataflow/deprecate-barrierguard-class
Dataflow: Deprecate BarrierGuard class
|
2022-06-22 10:44:08 +02:00 |
|
Rasmus Wriedt Larsen
|
abdcfd55c3
|
Python: uncertainty is treated as a certificate :O
|
2022-06-22 10:16:28 +02:00 |
|
Anders Schack-Mulligen
|
f8f9b7d3b4
|
Apply suggestions from code review
|
2022-06-21 14:11:36 +02:00 |
|
Asger F
|
092a6a01ac
|
Python: Update member documentation
|
2022-06-21 12:44:06 +02:00 |
|
Asger F
|
fecbfa6ca3
|
Python: add deprecation
|
2022-06-21 12:44:06 +02:00 |
|
Asger F
|
3a669a8d21
|
Python: getAValueReachingRhs -> getAValueReachingSink
|
2022-06-21 12:44:06 +02:00 |
|
Asger F
|
b096f9ec72
|
Python: Rename getAUse -> getAValueReachableFromSource
|
2022-06-21 12:44:06 +02:00 |
|
Asger F
|
181a53bd03
|
Python: Rename getAnImmediateUse -> asSource
|
2022-06-21 12:44:06 +02:00 |
|
Asger F
|
60fde3c031
|
Python: Rename getARhs -> asSink
|
2022-06-21 12:44:06 +02:00 |
|
Asger F
|
8f259d4bb6
|
Python: port API graph doc comment
|
2022-06-21 12:44:06 +02:00 |
|
Edoardo Pirovano
|
70dbd92e25
|
Bump minor version of all regularly released packs
|
2022-06-21 11:22:58 +01:00 |
|
Edoardo Pirovano
|
ad02b85efa
|
Merge branch main into rc/3.6
|
2022-06-21 11:15:25 +01:00 |
|
Anders Schack-Mulligen
|
a4796e1542
|
Add change notes.
|
2022-06-21 11:17:47 +02:00 |
|
Anders Schack-Mulligen
|
a6c0a9e480
|
Python: one more fix
|
2022-06-21 09:19:45 +02:00 |
|
Anders Schack-Mulligen
|
a7c268f804
|
Python: adjust test.
|
2022-06-20 15:46:38 +02:00 |
|
Anders Schack-Mulligen
|
f473a0a961
|
Python: Deprecate and replace BarrierGuard class.
|
2022-06-20 15:46:38 +02:00 |
|
yoff
|
94145e9e74
|
Update python/ql/lib/semmle/python/security/dataflow/TarSlipCustomizations.qll
|
2022-06-20 10:14:52 +02:00 |
|
Rasmus Wriedt Larsen
|
ae44a941f9
|
Merge pull request #9421 from RasmusWL/inline-brackets
Inline Expectation Tests: Allow `tag[foo bar]`
|
2022-06-20 10:01:19 +02:00 |
|
Taus
|
3a328f6a3f
|
Merge pull request #6570 from yoff/python/broaden-noqa-regex
Python: Broaden noqa regex to allow comments
|
2022-06-17 23:56:39 +02:00 |
|
Rasmus Wriedt Larsen
|
5fb41e4894
|
Inline Expectation Tests: Disallow tag[[[foo bar]
|
2022-06-17 17:36:04 +02:00 |
|
Rasmus Wriedt Larsen
|
f1b0a814e0
|
Python: Apply suggestions from code review
Co-authored-by: yoff <lerchedahl@gmail.com>
|
2022-06-17 15:04:57 +02:00 |
|
Anders Schack-Mulligen
|
6518a01ded
|
Dataflow: Sync.
|
2022-06-16 11:25:28 +02:00 |
|
Taus
|
9bf2eb55ca
|
Python: Allow whitespace before colon
As suggested by @DimitriPapadopolous.
Also fixes the test output to account for the `noqa` annotation (with
added comment) that we're now detecting.
|
2022-06-16 11:16:58 +02:00 |
|
Rasmus Lerchedahl Petersen
|
98301332bd
|
Python: Broaden noqa regex
|
2022-06-16 11:16:58 +02:00 |
|
Rasmus Wriedt Larsen
|
d6e68258a4
|
Python: API-graphs: allow class decorators in .getASubclass()
|
2022-06-15 17:30:34 +02:00 |
|