Erik Krogh Kristensen
|
81efd726cb
|
renamings - and simplifications of qldoc
|
2021-03-10 15:42:50 +01:00 |
|
Rasmus Lerchedahl Petersen
|
e4422fc939
|
Python, doc: Remove section on taint-tracking
|
2021-03-10 15:38:19 +01:00 |
|
Erik Krogh Kristensen
|
d3fca0a107
|
Apply suggestions from code review
Co-authored-by: Asger F <asgerf@github.com>
|
2021-03-10 15:24:05 +01:00 |
|
Erik Krogh Kristensen
|
c993f9a3a3
|
add instance methods in the same class to localFieldStep
|
2021-03-10 15:19:07 +01:00 |
|
Erik Krogh Kristensen
|
ea6d3bde9c
|
Update javascript/ql/src/semmle/javascript/dataflow/internal/CallGraphs.qll
Co-authored-by: Asger F <asgerf@github.com>
|
2021-03-10 15:00:48 +01:00 |
|
CodeQL CI
|
2c4ba561bf
|
Merge pull request #5360 from erik-krogh/regParse
Approved by asgerf
|
2021-03-10 05:57:19 -08:00 |
|
Geoffrey White
|
a2660e5996
|
Merge pull request #5326 from ihsinme/ihsinme-patch-244
CPP: Add query for CWE-20 Improper Input Validation
|
2021-03-10 13:53:26 +00:00 |
|
Tom Hvitved
|
fc5158c41c
|
Merge pull request #5338 from hvitved/dataflow/performance-tweaks
Data flow: Performance tweaks
|
2021-03-10 13:56:57 +01:00 |
|
Asger Feldthaus
|
fbca06f4e1
|
JS: Move TaintMetrics.qll into internal folder
|
2021-03-10 11:53:44 +00:00 |
|
Mathias Vorreiter Pedersen
|
0f6c56ad74
|
C++: Use names that better match the AST dataflow library.
|
2021-03-10 11:44:19 +01:00 |
|
Erik Krogh Kristensen
|
49b1bfc41b
|
add a step for referencing instance/static methods on classes
|
2021-03-10 10:57:28 +01:00 |
|
Rasmus Lerchedahl Petersen
|
76e936c64d
|
Python, doc: Add links to runs on LGTM.com
|
2021-03-10 10:52:22 +01:00 |
|
Anders Schack-Mulligen
|
ed250d5017
|
Merge pull request #5339 from smowton/smowton/feature/commons-regex-utils
Java: Add models for Commons-Lang's RegExUtils class
|
2021-03-10 10:23:37 +01:00 |
|
Chris Smowton
|
410f21cd55
|
Fix comment describing two-arg nextInt/nextLong
Co-authored-by: Marcono1234 <Marcono1234@users.noreply.github.com>
|
2021-03-10 08:43:37 +00:00 |
|
Rasmus Lerchedahl Petersen
|
91c0066b8b
|
Python: Make the documentation not lie
|
2021-03-09 18:17:51 +01:00 |
|
yoff
|
dfdf0344de
|
Update python/ql/src/Security/CWE-327/InsecureDefaultProtocol.qhelp
Co-authored-by: Felicity Chapman <felicitymay@github.com>
|
2021-03-09 16:44:08 +01:00 |
|
Chris Smowton
|
fa51af5be1
|
NBSP -> original-flavour space
|
2021-03-09 15:40:45 +00:00 |
|
Erik Krogh Kristensen
|
518bfa4d41
|
move getAnInstanceMemberAccess to ClassNode
|
2021-03-09 16:37:36 +01:00 |
|
Erik Krogh Kristensen
|
e8afafca7a
|
add another route-handler test
|
2021-03-09 16:37:36 +01:00 |
|
ihsinme
|
c281820f0f
|
Update LateCheckOfFunctionArgument.ql
|
2021-03-09 18:22:11 +03:00 |
|
ihsinme
|
07769c7322
|
Update LateCheckOfFunctionArgument.expected
|
2021-03-09 18:21:08 +03:00 |
|
Erik Krogh Kristensen
|
c95a8e6776
|
add change note
|
2021-03-09 16:17:33 +01:00 |
|
Erik Krogh Kristensen
|
11793800ad
|
support subrouters, and engine registrations with file extensions
|
2021-03-09 16:17:33 +01:00 |
|
Erik Krogh Kristensen
|
70b8cdee9b
|
add qhelp
|
2021-03-09 16:17:33 +01:00 |
|
Erik Krogh Kristensen
|
28951e98c4
|
add engine filter to js/template-object-injection
|
2021-03-09 16:17:33 +01:00 |
|
Erik Krogh Kristensen
|
b30484dd69
|
behaviour preserving refactorization into modules
|
2021-03-09 16:17:29 +01:00 |
|
Aditya Sharad
|
b1d0b9afbb
|
Merge pull request #5363 from github/adityasharad/actions/docs-review-fix
Actions: Fix comment that tags the Docs team
|
2021-03-09 07:17:24 -08:00 |
|
Chris Smowton
|
189b2215c5
|
Remove useless value from inline test expectations
|
2021-03-09 15:11:39 +00:00 |
|
Chris Smowton
|
e8f81c4f30
|
Improve change note
|
2021-03-09 15:11:13 +00:00 |
|
Chris Smowton
|
074d73e325
|
Add change note
|
2021-03-09 15:11:13 +00:00 |
|
Chris Smowton
|
9163893879
|
Add models for Commons-Lang's RegExUtils class
|
2021-03-09 15:11:13 +00:00 |
|
Tom Hvitved
|
fe6efde449
|
Address review comments
|
2021-03-09 14:30:12 +01:00 |
|
Rasmus Lerchedahl Petersen
|
8b25806a2c
|
Python: Attempt to clarify help
|
2021-03-09 13:29:33 +01:00 |
|
Rasmus Lerchedahl Petersen
|
a16de26799
|
Python: add linebreak to qhelp file
hopefully this will generate better markdown
|
2021-03-09 13:27:44 +01:00 |
|
yoff
|
fd5ac13828
|
Update python/ql/src/Security/CWE-327/InsecureDefaultProtocol.ql
Co-authored-by: Felicity Chapman <felicitymay@github.com>
|
2021-03-09 13:23:44 +01:00 |
|
yoff
|
88784fbd31
|
Update python/ql/src/Security/CWE-327/InsecureDefaultProtocol.qhelp
Co-authored-by: Felicity Chapman <felicitymay@github.com>
|
2021-03-09 13:23:35 +01:00 |
|
yoff
|
b6257edc9e
|
Update python/ql/src/Security/CWE-327/InsecureDefaultProtocol.qhelp
Co-authored-by: Felicity Chapman <felicitymay@github.com>
|
2021-03-09 13:20:19 +01:00 |
|
yoff
|
d5b304ce75
|
Update python/change-notes/2021-02-23-port-insecure-default-protocol.md
Co-authored-by: Felicity Chapman <felicitymay@github.com>
|
2021-03-09 13:19:48 +01:00 |
|
Taus
|
19b74e6e01
|
Merge pull request #5367 from tausbn/mergeback-rc/3.1-to-main
Merge rc/3.1 into main
|
2021-03-09 12:46:24 +01:00 |
|
Tamas Vajk
|
5480a31b68
|
Java: Remove MultipartFile.getSize/isEmpty from remote flow sources
|
2021-03-09 12:23:47 +01:00 |
|
Tamas Vajk
|
0d405c293a
|
Java: Convert PlayRequestGetMethod to CSV based flow source
|
2021-03-09 12:20:35 +01:00 |
|
Joe Farebrother
|
7a4ce83169
|
Merge pull request #5310 from joefarebrother/guava-io
Java: Add modelling for Guava IO utilities
|
2021-03-09 11:19:44 +00:00 |
|
Joe Farebrother
|
bd4a414abd
|
Remove CSV data from query
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2021-03-09 10:50:15 +00:00 |
|
Tamas Vajk
|
e0b1a86038
|
Java: Convert WebSocketMessageParameterSource to CSV based flow source
|
2021-03-09 11:49:59 +01:00 |
|
Tamas Vajk
|
193458eb3d
|
Java: Convert SpringRestTemplateResponseEntityMethod to CSV based flow source
|
2021-03-09 11:49:59 +01:00 |
|
Tamas Vajk
|
e0c51b510f
|
Java: Convert WebViewGetUrlMethod to CSV based flow source
|
2021-03-09 11:42:40 +01:00 |
|
Tamas Vajk
|
8ba820cae1
|
Java: Convert android XML get* methods to CSV based flow source
|
2021-03-09 11:42:13 +01:00 |
|
Tamas Vajk
|
09b0d824b4
|
Java: Convert org.apache.http.Http*.get* methods to CSV based flow source
|
2021-03-09 11:41:33 +01:00 |
|
Tamas Vajk
|
3c8ac5c789
|
Java: Convert Cookie.get* methods to CSV based flow source
|
2021-03-09 11:41:33 +01:00 |
|
Tamas Vajk
|
86cf143029
|
Java: Convert ServletRequestGetBodyMethod to CSV based flow source
|
2021-03-09 11:41:32 +01:00 |
|