Tony Torralba
|
ec8ffeed07
|
Add Intent URI Permission Manipulation query
|
2022-01-20 13:23:14 +01:00 |
|
Tony Torralba
|
c09b6691e1
|
Merge pull request #6171 from atorralba/atorralba/promote-unsafe-certificate-trust
Java: Promote Unsafe certificate trust query from experimental
|
2022-01-20 12:07:03 +01:00 |
|
Anders Schack-Mulligen
|
f154530141
|
Merge pull request #7662 from JLLeitschuh/patch-2
Fix typo in FileWritable
|
2022-01-20 11:13:59 +01:00 |
|
Benjamin Muskalla
|
8217873bae
|
Align files with new naming pattern
|
2022-01-20 11:02:53 +01:00 |
|
Anders Schack-Mulligen
|
4aa2661dc1
|
Merge pull request #7634 from bmuskalla/refactorLangModel
Refactor Apache Commons Lang model
|
2022-01-20 11:01:25 +01:00 |
|
Benjamin Muskalla
|
4cac35adad
|
Regnerate model to capture char[] APIs
|
2022-01-20 10:59:28 +01:00 |
|
Benjamin Muskalla
|
857c2778a6
|
Added missing model for ReadableByteChannel
This reveals more models for commons io
|
2022-01-20 10:59:28 +01:00 |
|
Benjamin Muskalla
|
b20b3ab480
|
Regenrate model to replace manual models
|
2022-01-20 10:59:27 +01:00 |
|
Benjamin Muskalla
|
93f6fde63c
|
Keep not-yet-covered models
|
2022-01-20 10:59:27 +01:00 |
|
Benjamin Muskalla
|
d07997699f
|
Introduce generated model for Commons IO
|
2022-01-20 10:59:24 +01:00 |
|
Erik Krogh Kristensen
|
4e8e3a7420
|
simplify expressions that could be type-casts
|
2022-01-20 10:41:35 +01:00 |
|
Tony Torralba
|
967308fbfd
|
Change InsecureTrustManagerConfiguration to DataFlow
|
2022-01-20 10:24:47 +01:00 |
|
Tony Torralba
|
7a1a45f5f9
|
QLDoc
|
2022-01-20 10:24:46 +01:00 |
|
Tony Torralba
|
ab4dc30f54
|
Refactor into libraries
|
2022-01-20 10:23:18 +01:00 |
|
github-actions[bot]
|
4ce8ccc52b
|
Release preparation for version 2.7.6
|
2022-01-20 08:21:18 +00:00 |
|
Jonathan Leitschuh
|
23548c50e1
|
Fix typo in FileWritable
|
2022-01-19 16:14:38 -05:00 |
|
Tony Torralba
|
695e77a219
|
Simplify isSslSocket predicate
|
2022-01-19 17:01:28 +01:00 |
|
Tony Torralba
|
e442e50e6b
|
Apply suggestions from code review
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2022-01-19 16:43:48 +01:00 |
|
Tony Torralba
|
101ad777e3
|
Move things around after rebase
|
2022-01-19 16:43:48 +01:00 |
|
Tony Torralba
|
000a544729
|
Decouple UnsafeCertTrust.qll to reuse the taint tracking configuration
|
2022-01-19 16:43:43 +01:00 |
|
Tony Torralba
|
d9e98ceacc
|
Consider setSslContextFactory and fix tests
|
2022-01-19 16:43:01 +01:00 |
|
Tony Torralba
|
4d207101e2
|
Fix QLDoc
|
2022-01-19 16:43:00 +01:00 |
|
Tony Torralba
|
19d1a780ca
|
Generalize sanitizer using local flow
|
2022-01-19 16:42:05 +01:00 |
|
Tony Torralba
|
64518bf91a
|
Handle a specific pass-by-reference flow issue
|
2022-01-19 16:42:04 +01:00 |
|
Tony Torralba
|
4508945f85
|
Fix assumption regarding when an SSLSocket does the TLS handhsake
|
2022-01-19 16:42:03 +01:00 |
|
Tony Torralba
|
5d4cd70f8c
|
Adjusted sources and sanitizer of UnsafeCertTrust taint tracking config
|
2022-01-19 16:42:02 +01:00 |
|
Tony Torralba
|
e43fff2d30
|
Use InlineExpectationsTest
|
2022-01-19 16:42:02 +01:00 |
|
Tony Torralba
|
02d0fa9188
|
Minor changes in QLDocs and a sanitizer's type
|
2022-01-19 16:42:01 +01:00 |
|
Tony Torralba
|
4313baf622
|
Big refactor:
- Move classes and predicates to appropriate libraries
- Overhaul the endpoint identification algorithm logic to use taint tracking
- Adapt tests
|
2022-01-19 16:42:00 +01:00 |
|
Tony Torralba
|
6096080156
|
Use all possible packages for Fragment classes
Also fix stub
|
2022-01-19 16:23:11 +01:00 |
|
Tony Torralba
|
3c9fac0c6e
|
Sync DataFlowImplForOnActivityResult.qll
|
2022-01-19 16:11:51 +01:00 |
|
Tony Torralba
|
6a4d2ee850
|
Apply code review suggestions
|
2022-01-19 16:08:31 +01:00 |
|
Tony Torralba
|
57ff13dd19
|
Sync DataFlowImplForOnActivityResult to latest changes
|
2022-01-19 16:08:31 +01:00 |
|
Tony Torralba
|
37916a8368
|
Fix previous merge
|
2022-01-19 16:08:31 +01:00 |
|
Tony Torralba
|
d9d9ad7d63
|
Use dedicated instance of DataFlow
|
2022-01-19 16:08:31 +01:00 |
|
Tony Torralba
|
aef63f69b0
|
Formatting
|
2022-01-19 16:08:30 +01:00 |
|
Tony Torralba
|
4b3029564c
|
Apply suggestions from code review
Co-authored-by: Chris Smowton <smowton@github.com>
|
2022-01-19 16:08:29 +01:00 |
|
Tony Torralba
|
c675028537
|
Add Fragment and Activity edge case
|
2022-01-19 16:08:28 +01:00 |
|
Tony Torralba
|
9ae1f1cf85
|
QLDoc
|
2022-01-19 16:08:27 +01:00 |
|
Tony Torralba
|
211cb9370f
|
Add the Intent parameter of onActivityResult as a source
|
2022-01-19 16:08:25 +01:00 |
|
Chris Smowton
|
84097468cc
|
Merge pull request #7286 from luchua-bc/java/unsafe-url-forward-dispatch
Java: CWE-552 Query to detect unsafe request dispatcher usage
|
2022-01-18 18:19:20 +00:00 |
|
Benjamin Muskalla
|
9e91b805d6
|
Sort Lang3 models
|
2022-01-18 18:10:37 +01:00 |
|
Benjamin Muskalla
|
e6800c877c
|
Merge Lang3 rows
|
2022-01-18 18:10:37 +01:00 |
|
Benjamin Muskalla
|
736e68820c
|
Split out Lang3 models
|
2022-01-18 18:10:37 +01:00 |
|
Benjamin Muskalla
|
67b60dcf78
|
Sort Lang2 rows
|
2022-01-18 18:10:36 +01:00 |
|
Benjamin Muskalla
|
82bda6d573
|
Merge Lang2 summary models
|
2022-01-18 18:10:36 +01:00 |
|
Benjamin Muskalla
|
8eb6743586
|
Split out Lang2 rows
|
2022-01-18 18:10:33 +01:00 |
|
Tony Torralba
|
b16b0270d2
|
Merge pull request #6779 from atorralba/atorralba/android-implicit-pending-intents
Java: CWE-927 - Query to detect the use of implicit PendingIntents
|
2022-01-18 12:14:47 +01:00 |
|
Chris Smowton
|
9819752bdd
|
Merge pull request #7526 from smowton/smowton/fix/restore-nodes-edges-consistency
Don't include arg -> param edges in PathGraph::edges where arg is not reachable
|
2022-01-18 11:05:47 +00:00 |
|
Benjamin Muskalla
|
7e215a5193
|
Merge pull request #7599 from bmuskalla/modelWriter
Java: Model Appenable and Writer
|
2022-01-18 11:55:27 +01:00 |
|