Owen Mansel-Chan
|
bedfe1e755
|
Apply suggestions from code review
Co-authored-by: Geoffrey White <40627776+geoffw0@users.noreply.github.com>
|
2026-03-24 22:06:53 +00:00 |
|
Owen Mansel-Chan
|
7e6319d648
|
Remove unused field
|
2026-03-24 10:39:32 +00:00 |
|
Owen Mansel-Chan
|
93231794ee
|
Document that MaD barriers for hardcoded credentials apply to all kinds
|
2026-03-24 10:39:05 +00:00 |
|
Owen Mansel-Chan
|
5762191832
|
Enable MaD barriers for queries with MaD sinks
|
2026-03-24 10:28:25 +00:00 |
|
Owen Mansel-Chan
|
fd8821fcb5
|
Merge pull request #21475 from owen-mc/rust/mad-barriers
Rust: Add support for defining barriers and barrier guards using models-as-data
|
2026-03-24 09:31:24 +00:00 |
|
Tom Hvitved
|
cc99867969
|
Merge pull request #21511 from hvitved/ruby/empty-stats
Ruby: Use empty DB stats
|
2026-03-24 08:25:43 +01:00 |
|
Mathias Vorreiter Pedersen
|
680ea0b960
|
Merge pull request #21552 from MathiasVP/more-public-dataflow-apis
C++: Expose indirect instructions and indirect parameters in dataflow
|
2026-03-23 17:46:14 +00:00 |
|
Mario Campos
|
a5763303fc
|
Merge pull request #21557 from github/rc/3.21
Merge back remaining changes from rc/3.21
|
2026-03-23 12:28:34 -05:00 |
|
Owen Mansel-Chan
|
8d16a2b4fa
|
Fix parameter -> argument in QLDoc
|
2026-03-23 16:24:03 +00:00 |
|
Owen Mansel-Chan
|
97ebc0e839
|
Update QLDoc in FlowBarrier.qll
|
2026-03-23 16:22:27 +00:00 |
|
Owen Mansel-Chan
|
d82fc67b36
|
Fix QLDoc formatting
|
2026-03-23 16:11:22 +00:00 |
|
Mathias Vorreiter Pedersen
|
8cebf510dc
|
C++: Reword the change note from #21458.
|
2026-03-23 13:45:46 +00:00 |
|
Mathias Vorreiter Pedersen
|
b5723bd75d
|
Merge branch 'main' into more-public-dataflow-apis
|
2026-03-23 13:43:01 +00:00 |
|
Mathias Vorreiter Pedersen
|
fef314e27f
|
C++: Add change note.
|
2026-03-23 13:39:15 +00:00 |
|
Mathias Vorreiter Pedersen
|
1363c54a9f
|
C++: Add 'asIndirectInstruction' as a public predicate.
|
2026-03-23 13:28:33 +00:00 |
|
Mathias Vorreiter Pedersen
|
09caeca7e9
|
C++: Move parameter indirection nodes into the public API.
|
2026-03-23 13:27:20 +00:00 |
|
Tom Hvitved
|
0d0d34cc71
|
Merge pull request #21498 from Gregro/csharp/fix-log-forging-extension-methods
C#: Fix false positives in cs/log-forging for extension methods
|
2026-03-23 11:24:12 +01:00 |
|
Jeroen Ketema
|
be245357cc
|
Merge pull request #21458 from github/jeongsoolee09/add-getIndirectionIndex
Add `IndirectUninitializedNode` and related helper predicates
|
2026-03-23 11:03:57 +01:00 |
|
Jeroen Ketema
|
ee00b98476
|
Update cpp/ql/lib/change-notes/2026-03-20-add-indirect-uninitialized-node.md
|
2026-03-23 10:44:21 +01:00 |
|
Jeongsoo Lee
|
6ae32f22a8
|
Merge branch 'main' into jeongsoolee09/add-getIndirectionIndex
|
2026-03-22 11:51:14 -04:00 |
|
Gregro
|
a59c865328
|
let interprocedural analysis handle source-available extension methods for LogForgingLogMessageSink's
|
2026-03-21 20:05:08 +00:00 |
|
Gregro
|
d0c48893f5
|
update test helper to use more robust .ReplaceLineEndings() sanitizer
|
2026-03-21 20:05:08 +00:00 |
|
Gregro
|
d99247cf13
|
Clarify static extension method class name
|
2026-03-21 20:05:08 +00:00 |
|
Gregro
|
a9eb801fea
|
C#: Fix false positives in cs/log-forging for extension methods
|
2026-03-21 20:05:08 +00:00 |
|
Tom Hvitved
|
9a4bc69843
|
Merge pull request #21510 from hvitved/ci/remove-ruby-checks
CI: Remove Ruby checks
|
2026-03-21 08:04:17 +01:00 |
|
Jeongsoo Lee
|
d4fef1c68e
|
Merge branch 'main' into jeongsoolee09/add-getIndirectionIndex
|
2026-03-20 10:01:05 -07:00 |
|
Jeongsoo Lee
|
d2fcced5ad
|
Add a feature change note
|
2026-03-20 09:59:12 -07:00 |
|
Owen Mansel-Chan
|
093c27955f
|
Fix incorrect QLDoc
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
|
2026-03-20 15:24:15 +00:00 |
|
Tom Hvitved
|
f99f26f908
|
Merge pull request #21464 from hvitved/rust/type-inference-trait-bound-impl-overlap
Rust: Disambiguate types inferred from trait bounds
|
2026-03-20 15:14:24 +01:00 |
|
Simon Friis Vindum
|
f6c81ff30a
|
Merge pull request #21512 from paldepind/cpp/extraction-information
C++: Add `cpp/extraction-information` query
|
2026-03-20 14:12:59 +01:00 |
|
Tom Hvitved
|
4b364639a2
|
Ruby: Fix join orders following DB stats removal
|
2026-03-20 13:13:38 +01:00 |
|
Owen Mansel-Chan
|
bde9378cee
|
Update MaD barrier guard test output
|
2026-03-20 11:10:08 +00:00 |
|
Owen Mansel-Chan
|
769b3a6aae
|
Instantiate flow barrier guards from MaD
|
2026-03-20 11:08:53 +00:00 |
|
Owen Mansel-Chan
|
7d65baccb2
|
Add FlowBarrierGuard to FlowBarrier.qll
|
2026-03-20 11:08:33 +00:00 |
|
Owen Mansel-Chan
|
77cb35380c
|
Add MaD barrier guard model to make test pass
|
2026-03-20 11:06:41 +00:00 |
|
Owen Mansel-Chan
|
c5457d3e30
|
Add (failing) test for MaD barrier guard
|
2026-03-20 11:06:39 +00:00 |
|
Owen Mansel-Chan
|
2f0d3288ce
|
Misc: fix typos in QLDocs
|
2026-03-20 11:06:38 +00:00 |
|
Owen Mansel-Chan
|
93c656065d
|
Add test for MaD barriers
|
2026-03-20 11:06:36 +00:00 |
|
Owen Mansel-Chan
|
e86ce8feed
|
Instantiate flow barriers from MaD
|
2026-03-20 11:06:35 +00:00 |
|
Owen Mansel-Chan
|
d3177b9e82
|
Add FlowBarrier.qll
|
2026-03-20 11:06:33 +00:00 |
|
Owen Mansel-Chan
|
f4550544ce
|
Shared: Add barrierElement in FlowSummaryImpl.qll
|
2026-03-20 11:06:32 +00:00 |
|
Owen Mansel-Chan
|
f9521e9e88
|
Update interpretModelForTest
|
2026-03-20 11:06:30 +00:00 |
|
Owen Mansel-Chan
|
f342bae962
|
Update empty.model.yml
|
2026-03-20 11:06:29 +00:00 |
|
Owen Mansel-Chan
|
bceab0b44e
|
Add extensible predicates
|
2026-03-20 11:06:26 +00:00 |
|
Jeroen Ketema
|
02f8984aff
|
Merge pull request #21522 from jketema/swift-linux-test
Swift: Fix typo
|
2026-03-20 12:04:27 +01:00 |
|
Jeroen Ketema
|
b63e34d467
|
Swift: Fix typo
|
2026-03-20 11:34:19 +01:00 |
|
Óscar San José
|
ec726f5941
|
Merge pull request #21486 from github/post-release-prep/codeql-cli-2.25.0
Post-release preparation for codeql-cli-2.25.0
|
2026-03-20 11:23:20 +01:00 |
|
Geoffrey White
|
208ae7aa01
|
Merge pull request #21514 from geoffw0/suspicioussizeof
C++: Fix an issue with cpp/suspicious-add-sizeof in BMN databases
|
2026-03-20 09:41:39 +00:00 |
|
Geoffrey White
|
be746b775b
|
Merge pull request #21493 from MarkLee131/fix/format-string-fp-in-printf-impl
C++: exclude printf implementation internals from uncontrolled format string sinks
|
2026-03-20 09:21:48 +00:00 |
|
Simon Friis Vindum
|
bc518c08c7
|
C++: Fix grammar in comment
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
|
2026-03-20 09:19:59 +01:00 |
|