Rasmus Wriedt Larsen
|
4d2a3b38d2
|
Merge pull request #8511 from RasmusWL/use-query-suffix
Python: Use `Query.qll` suffix for dataflow configuration definitions
|
2022-04-06 11:59:29 +02:00 |
|
Ahmed Farid
|
29f69bde75
|
Update zipslip_bad.py
|
2022-04-05 12:46:51 +00:00 |
|
Ahmed Farid
|
dfe7f532ac
|
Update CopyFile.qll
|
2022-04-05 12:42:05 +00:00 |
|
Ahmed Farid
|
0d6d07886b
|
Rename Zip.qll to CopyFile.qll
|
2022-04-05 12:37:14 +00:00 |
|
Ahmed Farid
|
8882bc1533
|
Update Frameworks.qll
|
2022-04-05 12:32:10 +00:00 |
|
Ahmed Farid
|
68bfe38529
|
Update Zip.qll
|
2022-04-05 12:31:30 +00:00 |
|
Rasmus Wriedt Larsen
|
5b96db26b3
|
Python: Rewrite concepts to use extends ... instanceof ...
This solved performance problems experienced in
https://github.com/github/codeql/pull/8634, and this commit+PR is to
ensure we get this change in as fast as possible.
|
2022-04-05 12:34:15 +02:00 |
|
Tom Hvitved
|
57f2a74636
|
Python: Implement ContentSet
|
2022-04-04 13:51:44 +02:00 |
|
Tom Hvitved
|
c4fbc618a9
|
Data flow: Sync files
|
2022-04-04 13:51:44 +02:00 |
|
Tom Hvitved
|
50dc3820c6
|
Merge pull request #8589 from hvitved/regex/speedup-concretise
|
2022-04-03 17:56:07 +02:00 |
|
github-actions[bot]
|
6af568b16d
|
Post-release preparation for codeql-cli-2.8.5
|
2022-04-01 16:22:14 +00:00 |
|
Chris Smowton
|
3119885a9b
|
Merge pull request #8638 from smowton/smowton/docs/additional-flow-step-description
Improve wording of isAdditionalFlow/TaintStep qldoc
|
2022-04-01 16:41:04 +01:00 |
|
Chris Smowton
|
28fa49dcd6
|
dataflow -> data-flow
|
2022-04-01 13:22:58 +01:00 |
|
Rasmus Wriedt Larsen
|
ba011fb13f
|
Merge pull request #8601 from zbazztian/recognize-flask-named-body-param
Python: Flask: Identify body contents passed via named response parameter in invocations of Response constructor
|
2022-04-01 14:19:28 +02:00 |
|
Sebastian Bauersfeld
|
504e7e4a55
|
Update python/ql/lib/change-notes/2022-03-30-flask-recognize-body-param.md
Co-authored-by: Rasmus Wriedt Larsen <rasmuswriedtlarsen@gmail.com>
|
2022-04-01 18:41:27 +07:00 |
|
Erik Krogh Kristensen
|
eae2a6af36
|
update expected output for Locations.ql
|
2022-04-01 12:58:00 +02:00 |
|
Erik Krogh Kristensen
|
ed7e1206ff
|
rename isBeforeCode to isCommentAfterCode
|
2022-04-01 12:55:00 +02:00 |
|
github-actions[bot]
|
ee746d20df
|
Release preparation for version 2.8.5
|
2022-04-01 10:39:31 +00:00 |
|
Chris Smowton
|
3b0bd3bc0f
|
Improve wording
|
2022-04-01 11:31:31 +01:00 |
|
Chris Smowton
|
99026a6071
|
Improve wording of isAdditionalFlow/TaintStep qldoc
|
2022-04-01 11:07:27 +01:00 |
|
Tom Hvitved
|
46d69cf544
|
Regex: Further tweaks to concretise computations
|
2022-03-31 12:52:43 +02:00 |
|
Tom Hvitved
|
5181544790
|
Sync shared files
|
2022-03-31 12:52:42 +02:00 |
|
Tom Hvitved
|
0fb28f4bc9
|
Sync shared files
|
2022-03-31 12:52:42 +02:00 |
|
Erik Krogh Kristensen
|
1218c4f4ed
|
fix ql/name-casing, and drive-by QL-for-QL typo fix
|
2022-03-30 22:59:14 +02:00 |
|
Erik Krogh Kristensen
|
1847a5713b
|
remove TODO
|
2022-03-30 22:54:01 +02:00 |
|
Erik Krogh Kristensen
|
7ca6426ea5
|
revert the Taint stage, as it caused an alert for ql/abstract-class-import
|
2022-03-30 22:54:01 +02:00 |
|
Erik Krogh Kristensen
|
7e4ab4c60b
|
Revert "import all the frameworks that extend RegexString"
This reverts commit 84bc9042de4e876685f8f5ffdd88893383d1cfdc.
It caused ql/abstract-class-import alerts
|
2022-03-30 22:54:01 +02:00 |
|
Erik Krogh Kristensen
|
3b9335c051
|
nomagic on containsInScope
|
2022-03-30 22:54:01 +02:00 |
|
Erik Krogh Kristensen
|
5caff81ff9
|
import all the frameworks that extend RegexString
|
2022-03-30 22:54:01 +02:00 |
|
Erik Krogh Kristensen
|
b959705531
|
revert changes in MRO.qll
|
2022-03-30 22:54:01 +02:00 |
|
Erik Krogh Kristensen
|
b74852ffd6
|
cache a bit more (again)
|
2022-03-30 22:54:01 +02:00 |
|
Erik Krogh Kristensen
|
d9ced55e2c
|
make private predicates private
|
2022-03-30 22:54:01 +02:00 |
|
Erik Krogh Kristensen
|
040196f40d
|
cache more basicblock predicates
|
2022-03-30 22:54:01 +02:00 |
|
Erik Krogh Kristensen
|
79713e0ef8
|
a bit more caching
|
2022-03-30 22:54:00 +02:00 |
|
Erik Krogh Kristensen
|
7643aac207
|
revert bad nomagic
|
2022-03-30 22:54:00 +02:00 |
|
Erik Krogh Kristensen
|
35c7fa58a7
|
joiner order fixes
|
2022-03-30 22:54:00 +02:00 |
|
Erik Krogh Kristensen
|
88e896992e
|
cache the remainder of the pointsto layer
|
2022-03-30 22:54:00 +02:00 |
|
Erik Krogh Kristensen
|
79da0970cc
|
various join order fixes
|
2022-03-30 22:54:00 +02:00 |
|
Erik Krogh Kristensen
|
3e9ee887d4
|
fix bad mistake
|
2022-03-30 22:54:00 +02:00 |
|
Erik Krogh Kristensen
|
758a5d7a85
|
few join order fixes
|
2022-03-30 22:54:00 +02:00 |
|
Erik Krogh Kristensen
|
6eca4ba2d3
|
get around identical files by adding the ref() call somewhere else
|
2022-03-30 22:54:00 +02:00 |
|
Erik Krogh Kristensen
|
4089788629
|
revert caching of some large predicates that caused the DB size to increase too much
|
2022-03-30 22:54:00 +02:00 |
|
Erik Krogh Kristensen
|
0da80f90d3
|
rename the SSA stages to AST
|
2022-03-30 22:54:00 +02:00 |
|
Erik Krogh Kristensen
|
c9e3a62953
|
cached stages iteration 5
|
2022-03-30 22:54:00 +02:00 |
|
Erik Krogh Kristensen
|
a8f9a91e38
|
cached stages iteration 4
|
2022-03-30 22:54:00 +02:00 |
|
Erik Krogh Kristensen
|
f68357a063
|
cached stages iteration 3.5
|
2022-03-30 22:54:00 +02:00 |
|
Erik Krogh Kristensen
|
37a9b41e26
|
cached stages iteration 3
|
2022-03-30 22:54:00 +02:00 |
|
Erik Krogh Kristensen
|
60b5af215f
|
cached stages iteration 2
|
2022-03-30 22:53:59 +02:00 |
|
Erik Krogh Kristensen
|
71eacea90b
|
add the cached stages pattern to Python
|
2022-03-30 22:53:59 +02:00 |
|
Sebastian Bauersfeld
|
a3c3a7fe0d
|
Python: Identify alternative body argument in invocations of Response constructor.
|
2022-03-30 19:34:54 +07:00 |
|