Tony Torralba
|
6f2d91a8ad
|
Sinks for CloseableThreadContext
|
2021-12-17 09:17:04 +01:00 |
|
Tony Torralba
|
7d6cba77a0
|
Add tests
|
2021-12-16 13:44:01 +01:00 |
|
Tony Torralba
|
2e0ca6ce2b
|
Add stubs
|
2021-12-16 13:44:01 +01:00 |
|
Tony Torralba
|
7d70b77141
|
Add new sinks and taint steps
|
2021-12-16 13:43:58 +01:00 |
|
Henry Mercer
|
5696146179
|
Java: Convert telemetry queries to summary metrics
Use the support for summary metrics with messages that'll be in the next
version of the CodeQL CLI.
|
2021-12-15 17:59:01 +00:00 |
|
luchua-bc
|
29ce0e9ef1
|
Add sanitizer for virtual method calls
|
2021-12-15 16:19:50 +00:00 |
|
Tony Torralba
|
6dfe0ce7c5
|
Adapt chage note to new format
|
2021-12-15 16:57:20 +01:00 |
|
Tony Torralba
|
f0e9b768f2
|
Apply suggestions from code review
Co-authored-by: Felicity Chapman <felicitymay@github.com>
|
2021-12-15 16:53:47 +01:00 |
|
Tony Torralba
|
65b6c16254
|
Fix stub after merge
|
2021-12-15 16:53:47 +01:00 |
|
Tony Torralba
|
6363ff3c08
|
QLDoc
|
2021-12-15 16:53:46 +01:00 |
|
Tony Torralba
|
85526d71da
|
Add Fragment injection in PreferenceActivity query
|
2021-12-15 16:53:46 +01:00 |
|
Tony Torralba
|
701d12fb5b
|
Add Fragment injection query
|
2021-12-15 16:53:45 +01:00 |
|
Tony Torralba
|
efb471687c
|
Add stubs
|
2021-12-15 16:53:42 +01:00 |
|
Tony Torralba
|
c1e4c05aa2
|
Update change note to new format
|
2021-12-15 13:08:34 +01:00 |
|
Tony Torralba
|
e2022f467c
|
Update java/ql/lib/semmle/code/java/dataflow/internal/TaintTrackingUtil.qll
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2021-12-15 13:00:16 +01:00 |
|
Tony Torralba
|
a3b25f0eb5
|
Don't consider subtypes of fields
|
2021-12-15 13:00:16 +01:00 |
|
Tony Torralba
|
47002a3bd7
|
Fix test
|
2021-12-15 13:00:16 +01:00 |
|
Tony Torralba
|
1426c5b406
|
Consider parameterized types
|
2021-12-15 13:00:16 +01:00 |
|
Tony Torralba
|
5e80044f11
|
Preserve taint on field-read-steps on entrypoint types
|
2021-12-15 13:00:15 +01:00 |
|
github-actions[bot]
|
59da2cdf69
|
Release preparation for version 2.7.4
|
2021-12-14 21:35:09 +00:00 |
|
Dave Bartolomeo
|
a62f181d42
|
Move new change notes to appropriate packs
|
2021-12-14 12:05:15 -05:00 |
|
Tony Torralba
|
68a0efaf0c
|
Formatting
|
2021-12-14 14:53:38 +01:00 |
|
Bas van Schaik
|
d85ed9ea7a
|
Clarify Log4jJndiInjection.ql query help
|
2021-12-14 12:32:36 +00:00 |
|
Chris Smowton
|
85ff57bae6
|
Merge pull request #7354 from atorralba/atorralba/log4j-rce-experimental-query
Java: Experimental query for Log4j JNDI Injection
|
2021-12-14 11:32:13 +00:00 |
|
Tony Torralba
|
aee617f911
|
Autoformat
|
2021-12-14 08:40:30 +01:00 |
|
Tony Torralba
|
1b761b3d12
|
Apply suggestions from code review
|
2021-12-13 20:38:06 +01:00 |
|
Tony Torralba
|
ff2f5a5f91
|
Apply suggestions from code review
Co-authored-by: Bas van Schaik <5082246+sj@users.noreply.github.com>
|
2021-12-13 19:44:38 +01:00 |
|
Tony Torralba
|
d2dc19900f
|
Apply suggestions from code review
Co-authored-by: Bas van Schaik <5082246+sj@users.noreply.github.com>
Co-authored-by: Marcono1234 <Marcono1234@users.noreply.github.com>
|
2021-12-13 19:39:52 +01:00 |
|
Andrew Eisenberg
|
0669ef505e
|
Fix semver for upgrades references
Ensure the version range is flexible enough to handle
future version changes.
|
2021-12-13 09:03:33 -08:00 |
|
Andrew Eisenberg
|
66c1629974
|
Merge pull request #7285 from github/post-release-prep-2.7.3-ddd4ccbb
Post-release preparation 2.7.3
|
2021-12-10 09:59:45 -08:00 |
|
Tony Torralba
|
43a10457dd
|
[Java] Query for Log4j JNDI Injection
|
2021-12-10 17:37:43 +01:00 |
|
Anders Schack-Mulligen
|
464b9c3991
|
Dataflow: Sync.
|
2021-12-10 11:20:01 +01:00 |
|
Anders Schack-Mulligen
|
32cb8f362b
|
Dataflow: Add test for FlowState.
|
2021-12-10 11:20:01 +01:00 |
|
Anders Schack-Mulligen
|
219bf51ec2
|
Dataflow: Add support for flow state.
|
2021-12-10 11:20:01 +01:00 |
|
Chris Smowton
|
753d886b0d
|
Merge pull request #6319 from haby0/java/MyBatisSqlInjection
[Java] CWE-089 MyBatis Mapper Sql Injection
|
2021-12-09 19:57:18 +00:00 |
|
Chris Smowton
|
75f3ebf051
|
Fix OTHER XML tag
|
2021-12-09 17:55:03 +00:00 |
|
Chris Smowton
|
9f69c75c50
|
Fix XML tag
|
2021-12-09 17:44:49 +00:00 |
|
Chris Smowton
|
2cd70b96cd
|
Fix doctype
|
2021-12-09 17:44:08 +00:00 |
|
Chris Smowton
|
470256da85
|
Copyedit
|
2021-12-09 15:10:07 +00:00 |
|
Chris Smowton
|
d0a19fffee
|
Copyedit
|
2021-12-09 14:58:29 +00:00 |
|
Tony Torralba
|
38250b0821
|
Remove unnecessary implicit read step
|
2021-12-09 15:18:38 +01:00 |
|
Tony Torralba
|
522a4bb9fa
|
Propagate extras through build methods
|
2021-12-09 14:56:52 +01:00 |
|
Tony Torralba
|
c0c40cc05b
|
Remove synthetic fields
|
2021-12-09 13:34:41 +01:00 |
|
Tony Torralba
|
3a3c7fc59e
|
Fix stub
|
2021-12-09 13:34:41 +01:00 |
|
Tony Torralba
|
f209ff4f76
|
Use synthetic fields to improve taint precision
|
2021-12-09 13:34:39 +01:00 |
|
Tony Torralba
|
b7f7c5ba20
|
Change format of fluent models to make review easier
|
2021-12-09 13:33:19 +01:00 |
|
Tony Torralba
|
f63ffb0630
|
Add models for Notification builders
|
2021-12-09 13:33:17 +01:00 |
|
haby0
|
8bcbf8e30f
|
rename isMybatisCollectionTypeSqlInjection
|
2021-12-09 09:16:33 +08:00 |
|
haby0
|
a18aad8536
|
Fix one
|
2021-12-08 21:03:17 +08:00 |
|
Anders Schack-Mulligen
|
38d0bb4a60
|
Merge pull request #7260 from hvitved/dataflow/argument-parameter-matching
Data flow: Introduce `ParameterPosition` and `ArgumentPosition`
|
2021-12-08 12:49:08 +01:00 |
|