Tom Hvitved
|
bd0a196a39
|
Java: Update data-flow caching
|
2021-04-27 19:06:39 +02:00 |
|
Tom Hvitved
|
914184f3dd
|
Data flow: Sync files
|
2021-04-27 19:06:39 +02:00 |
|
Tom Hvitved
|
37377644c9
|
Merge pull request #5781 from hvitved/java/predictable-seed-df6
Java: Use separate data-flow copy for `PredictableSeedFlowConfiguration`
|
2021-04-27 19:01:55 +02:00 |
|
Tamás Vajk
|
4cc88662e2
|
Merge pull request #5557 from tamasvajk/feature/java-sinks-csv
Java: convert sinks to CSV
|
2021-04-27 15:58:09 +02:00 |
|
Tamas Vajk
|
5b79094f34
|
Fix naming in HTTPS URL check
|
2021-04-27 14:59:52 +02:00 |
|
Tamas Vajk
|
e08b629cb5
|
Add documentation for URL opening sinks
|
2021-04-27 10:32:41 +02:00 |
|
Tom Hvitved
|
017beb6786
|
Java: Use separate data-flow copy for PredictableSeedFlowConfiguration
|
2021-04-27 10:07:33 +02:00 |
|
Chris Smowton
|
455b840712
|
Fix all dead qhelp links
For those documents with no obvious new home I've pointed the links to the Internet Archive.
|
2021-04-23 15:20:21 +01:00 |
|
Anders Schack-Mulligen
|
bc8c55836a
|
Merge pull request #5743 from aschackmull/java/flow-summary-tweaks
Java/C#: Move a couple of flow summary tweaks to the shared implementation.
|
2021-04-23 13:46:04 +02:00 |
|
Tamás Vajk
|
43dc9bbc94
|
Merge pull request #5744 from tamasvajk/feature/java-loc
Java: Introduce LoC summary metric query
|
2021-04-23 11:39:42 +02:00 |
|
Tamás Vajk
|
cb28bc80b7
|
Merge branch 'main' into feature/java-sinks-csv
|
2021-04-22 11:41:18 +02:00 |
|
Tamas Vajk
|
7134eb9079
|
Improve documentation of csv sink models
|
2021-04-22 11:37:41 +02:00 |
|
Tamas Vajk
|
1caa5c4780
|
Adjust hostname verifier sink identifier name
|
2021-04-22 11:22:18 +02:00 |
|
Tamas Vajk
|
6c78a247f2
|
Revert erroneous refactoring in header splitting sink base class
|
2021-04-22 11:20:39 +02:00 |
|
Tamas Vajk
|
9b1c54e81b
|
Add argument indices to HTTP header splitting sinks
|
2021-04-22 11:17:25 +02:00 |
|
Tamas Vajk
|
180904e9f6
|
Revert "Java: Convert Google HTTP client API parseAs sink to CSV format"
This reverts commit 3e53484bb3.
|
2021-04-22 11:14:51 +02:00 |
|
Owen Mansel-Chan
|
fea9f5f431
|
Merge pull request #5746 from owen-mc/java/refactor-exec-tainted
Make ExecTainted easier to extend
|
2021-04-22 10:14:28 +01:00 |
|
Owen Mansel-Chan
|
8a01799fb8
|
Make imports private
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2021-04-22 09:46:49 +01:00 |
|
Owen Mansel-Chan
|
4b8d4f5bbd
|
Update docs
|
2021-04-22 09:30:50 +01:00 |
|
Owen Mansel-Chan
|
e448dcb725
|
Avoid bad join order
We want to avoid joining on `i` first.
|
2021-04-22 09:30:49 +01:00 |
|
Owen Mansel-Chan
|
9f1704560b
|
Include constructors in abstract class
|
2021-04-22 09:30:48 +01:00 |
|
Tamás Vajk
|
9c936867fa
|
Exclude code from XML files
Co-authored-by: yo-h <55373593+yo-h@users.noreply.github.com>
|
2021-04-22 09:00:31 +02:00 |
|
Chris Smowton
|
94f0a1532d
|
Merge pull request #5682 from smowton/smowton/docs/fix-has-modifier-comment
Fix documentation of Modifier.qll
|
2021-04-21 15:41:29 +01:00 |
|
Owen Mansel-Chan
|
9c72e73a82
|
Make ExecTainted easier to extend
To add a method that executes a command, you can now define a class
extending ExecMethod.
|
2021-04-21 14:55:37 +01:00 |
|
Tamas Vajk
|
e25305e3cc
|
Java: Introduce LoC summary metric query
|
2021-04-21 14:27:00 +02:00 |
|
Anders Schack-Mulligen
|
f9599da32d
|
Java/C#: Move a couple of flow summary tweaks to the shared implementation.
|
2021-04-21 14:24:15 +02:00 |
|
Anders Schack-Mulligen
|
9362ae0687
|
Merge pull request #5422 from tamasvajk/feature/sink-migration-ldap
Java: Migrate LDAP injection sinks to CSV format
|
2021-04-21 10:05:28 +02:00 |
|
yo-h
|
00137f2905
|
Merge pull request #5721 from github/yo-h/java-diagnostic-queries
Java: add extractor `diagnostic` queries
|
2021-04-20 13:36:49 -04:00 |
|
Tamas Vajk
|
583513bafd
|
Fix review findings
|
2021-04-20 16:28:47 +02:00 |
|
Chris Smowton
|
9bfb0d93ca
|
Autoformat QL
|
2021-04-20 13:59:09 +01:00 |
|
Chris Smowton
|
0ec3ee29e4
|
Style last use of SecureASTCustomizer
|
2021-04-20 12:44:49 +01:00 |
|
Hayk Andriasyan
|
bb58a50503
|
Update GroovyInjection.qhelp
|
2021-04-20 15:41:58 +04:00 |
|
p0wn4j
|
f2de440886
|
[Java] CWE-094: Query to detect Groovy Code Injections
|
2021-04-20 19:18:24 +04:00 |
|
yo-h
|
87cd72496c
|
Java: add extractor diagnostic queries
|
2021-04-19 15:34:16 -04:00 |
|
yo-h
|
cb524b6c19
|
Merge pull request #5611 from github/yo-h/java16
Java: adjust test `options` for JDK 16 upgrade
|
2021-04-19 15:12:23 -04:00 |
|
Anders Schack-Mulligen
|
80eb0a2df6
|
Apply suggestions from code review
Co-authored-by: Chris Smowton <smowton@github.com>
|
2021-04-19 15:45:58 +02:00 |
|
Anders Schack-Mulligen
|
7d84cfacef
|
Java: Add MapKeyContent and MapValueContent.
|
2021-04-19 14:06:27 +02:00 |
|
Anders Schack-Mulligen
|
39862740e0
|
Java: Convert support for fluent interfaces.
|
2021-04-19 14:06:27 +02:00 |
|
Anders Schack-Mulligen
|
579c955892
|
Java: Adjust some tests.
|
2021-04-19 14:06:27 +02:00 |
|
Anders Schack-Mulligen
|
175c71221a
|
Java: Adjust some test output with more edges/nodes.
|
2021-04-19 14:06:27 +02:00 |
|
Anders Schack-Mulligen
|
60965b0d8c
|
Java: Adjust some csv models.
|
2021-04-19 14:02:19 +02:00 |
|
Anders Schack-Mulligen
|
a27dac029f
|
Java: Use shared flow summary library for csv models.
|
2021-04-19 14:02:19 +02:00 |
|
Anders Schack-Mulligen
|
29aec0d770
|
Java: Adjust expected output.
|
2021-04-19 13:16:46 +02:00 |
|
Anders Schack-Mulligen
|
c5193cf03f
|
Apply suggestions from code review
|
2021-04-19 13:14:56 +02:00 |
|
Anders Schack-Mulligen
|
06514159be
|
Java: Add XXE tests.
|
2021-04-19 10:58:21 +02:00 |
|
Anders Schack-Mulligen
|
daad62c4e0
|
Java: Add TaintedPath test.
|
2021-04-19 10:07:03 +02:00 |
|
Mathias Vorreiter Pedersen
|
e36b42a03f
|
Java: Fix invalid id in experimental query
The invalid id broke CI here: https://github.com/github/codeql/pull/5703 (see https://github.slack.com/archives/CPSEA0G22/p1618602834224600)
|
2021-04-17 09:47:15 +02:00 |
|
Anders Schack-Mulligen
|
605f28f741
|
Merge pull request #5686 from smowton/haby0/JsonHijacking
Java: JSONP Injection w/cleanups
|
2021-04-16 11:09:17 +02:00 |
|
Chris Smowton
|
c37994089c
|
Revert changes to unrelated query
|
2021-04-15 16:24:29 +01:00 |
|
Chris Smowton
|
254de76078
|
Remove unnecessary stubs
|
2021-04-15 16:20:27 +01:00 |
|