Jonathan Leitschuh
|
5b651f29d8
|
Fix insufficient tests and add documentation
|
2022-03-07 16:39:40 -05:00 |
|
Taus
|
af7f532212
|
Python: Fix up a bunch of function QLDoc
|
2022-03-07 18:59:49 +00:00 |
|
Jonathan Leitschuh
|
b282c7f1b9
|
Apply suggestions from code review
Co-authored-by: Marcono1234 <Marcono1234@users.noreply.github.com>
Co-authored-by: Chris Smowton <smowton@github.com>
|
2022-03-07 11:31:32 -05:00 |
|
Jonathan Leitschuh
|
523ddb79f3
|
Cleanup after code review feedback
|
2022-03-04 15:35:01 -05:00 |
|
Jonathan Leitschuh
|
5243fe3dbf
|
Apply suggestions from code review
Co-authored-by: Chris Smowton <smowton@github.com>
|
2022-03-04 15:30:52 -05:00 |
|
Jonathan Leitschuh
|
38897f2ec1
|
Fixup tests from code review changes
|
2022-03-04 09:33:51 -05:00 |
|
Jonathan Leitschuh
|
17b6e66814
|
Apply suggestions from code review
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com>
|
2022-03-04 09:29:57 -05:00 |
|
Joe Farebrother
|
6c05f7a81a
|
remove url from sensitive info regex
|
2022-03-04 10:37:05 +00:00 |
|
Jonathan Leitschuh
|
7ab193dde2
|
Add System.getProperties().getProperty support
|
2022-03-03 20:08:38 -05:00 |
|
Jonathan Leitschuh
|
04cd0dbfe9
|
[Java] Add CharacterLiteral to CompileTimeConstantExpr.getStringValue
|
2022-03-03 18:08:17 -05:00 |
|
Jonathan Leitschuh
|
31527a67e5
|
Refactor OS Checks & SystemProperty logic from review feedback
|
2022-03-03 17:15:35 -05:00 |
|
Jonathan Leitschuh
|
103c770ce7
|
Apply suggestions from code review
Co-authored-by: Chris Smowton <smowton@github.com>
|
2022-03-03 16:39:45 -05:00 |
|
Joe Farebrother
|
4ad402f33f
|
Move from experimental to main
|
2022-03-03 12:13:14 +00:00 |
|
Jonathan Leitschuh
|
fea50065f5
|
Fix duplicated comment
|
2022-03-02 19:54:04 -05:00 |
|
Jonathan Leitschuh
|
85de9f305e
|
Fix naming of OSCheck method
|
2022-03-02 19:41:46 -05:00 |
|
Jonathan Leitschuh
|
a7adbb7291
|
Refactor more system property access logic
|
2022-03-02 19:33:05 -05:00 |
|
Jonathan Leitschuh
|
3c53a05e16
|
Add OS Checks based upon separator or path separator
|
2022-03-02 14:15:56 -05:00 |
|
Jonathan Leitschuh
|
82d3cd8924
|
Improve system property lookup
|
2022-03-02 12:51:15 -05:00 |
|
Jonathan Leitschuh
|
dad9a02fbd
|
Update TempDirInfoDisclosure with new OS Guards
|
2022-03-02 12:51:15 -05:00 |
|
Jonathan Leitschuh
|
5913c9acad
|
Refactor OS Guard Checks
|
2022-03-02 12:51:14 -05:00 |
|
Jonathan Leitschuh
|
fd63107edf
|
Update OS Check from Review Feedback
|
2022-03-02 12:51:12 -05:00 |
|
Jonathan Leitschuh
|
9f5022ee95
|
Review fixup and add test for apache SystemUtils
|
2022-03-02 12:50:38 -05:00 |
|
Jonathan Leitschuh
|
49513443f2
|
Update java/ql/lib/semmle/code/java/os/OSCheck.qll
Co-authored-by: Marcono1234 <Marcono1234@users.noreply.github.com>
|
2022-03-02 12:50:37 -05:00 |
|
Jonathan Leitschuh
|
3cdfc00542
|
Cleanup from review feedback
|
2022-03-02 12:50:37 -05:00 |
|
Jonathan Leitschuh
|
39828fd596
|
Apply OS guard checks to TempDirLocalInformationDisclosure
|
2022-03-02 12:50:37 -05:00 |
|
Jonathan Leitschuh
|
cd073a2173
|
Java: Add Guard Classes for checking OS
|
2022-03-02 12:50:35 -05:00 |
|
Tamás Vajk
|
94cb5c2be4
|
Merge pull request #8296 from github/post-release-prep/codeql-cli-2.8.2
Post-release preparation for codeql-cli-2.8.2
|
2022-03-01 11:57:36 +01:00 |
|
github-actions[bot]
|
980f822983
|
Post-release preparation for codeql-cli-2.8.2
|
2022-03-01 09:24:30 +00:00 |
|
Michael Nebel
|
7bde1cbfb3
|
Java: Add case for Synthetic Fields in isRelevantTaintStep.
|
2022-03-01 09:15:01 +01:00 |
|
Michael Nebel
|
24640c3670
|
Java: Make a testcase for wrappers of sources.
|
2022-02-28 16:57:36 +01:00 |
|
Michael Nebel
|
66fe0e74b5
|
Java: Don't require that the source is directly within the TargetApi itself (in that case wrappers get excluded).
|
2022-02-28 16:48:23 +01:00 |
|
Michael Nebel
|
4a0b2b64b3
|
Java: Explicitly tie ReturnNode to TargetApi before calling returnNodeAsOutput.
|
2022-02-28 16:48:23 +01:00 |
|
Tom Hvitved
|
44949b6353
|
Java: Add bindingset to returnNodeAsOutput
|
2022-02-28 16:48:23 +01:00 |
|
Anders Schack-Mulligen
|
908cc40c9f
|
Java: Fix bug in model flow sanitizer.
|
2022-02-28 16:48:23 +01:00 |
|
Anders Schack-Mulligen
|
16a5ccddea
|
Java: Simplify model generator query using flow state.
|
2022-02-28 16:48:23 +01:00 |
|
Ian Lynagh
|
1e62b485a5
|
Merge pull request #8241 from igfoo/igfoo/stats4
Java: Update stats and make some performance tweaks
|
2022-02-28 12:58:06 +00:00 |
|
luchua-bc
|
88d9694628
|
Query to detect insecure WebResourceResponse implementation
|
2022-02-26 02:03:35 +00:00 |
|
Chris Smowton
|
f981fee37d
|
Adjust test expectation
|
2022-02-25 20:05:06 +00:00 |
|
Chris Smowton
|
ff5d680837
|
Add missing substitution description
|
2022-02-25 19:12:25 +00:00 |
|
Ian Lynagh
|
0bf1370cd5
|
Java: Autoformat QL
|
2022-02-25 19:08:08 +00:00 |
|
Chris Smowton
|
8fbd8c52dd
|
Fix test expectations
|
2022-02-25 17:35:52 +00:00 |
|
Chris Smowton
|
ff303db034
|
Autoformat and fix qhelp
|
2022-02-25 17:33:08 +00:00 |
|
Chris Smowton
|
303927c9c9
|
Fix qhelp
|
2022-02-25 17:33:08 +00:00 |
|
Chris Smowton
|
e02a3d0ddd
|
Rename qlref file
|
2022-02-25 17:33:08 +00:00 |
|
Ahmed Farid
|
3a2d514b18
|
Create ComparingValueOfSensetiveHeader.qlref
|
2022-02-25 17:33:08 +00:00 |
|
Ahmed Farid
|
0d278f6d61
|
Create Test.java
|
2022-02-25 17:33:08 +00:00 |
|
Ahmed Farid
|
1bc5fe13eb
|
Update and rename java/ql/test/experimental/query-tests/security/CWE-208/TimingAttackAgainstHeader.expected to java/ql/test/experimental/query-tests/security/CWE-208/TimingAttackAgainstHeader/TimingAttackAgainstHeader.expected
|
2022-02-25 17:33:08 +00:00 |
|
Ahmed Farid
|
63133f7e8b
|
Update TimingAttackAgainstHeader.expected
|
2022-02-25 17:33:08 +00:00 |
|
Ahmed Farid
|
f2457dafb5
|
Create TimingAttackAgainstHeader.expected
|
2022-02-25 17:33:08 +00:00 |
|
Ahmed Farid
|
35abc3f9a3
|
Update and rename ComparingValueOfSensetiveHeader.java to Test.java
|
2022-02-25 17:33:08 +00:00 |
|