Ed Minnix
|
c67b984fff
|
Refactor RandomQuery.qll
|
2023-03-29 22:33:09 -04:00 |
|
Ed Minnix
|
2698b61514
|
Refactor HardcodedCredentialsApiCall.qll
|
2023-03-29 22:33:08 -04:00 |
|
Ed Minnix
|
e8f7e3fcf1
|
Refactor ExternalAPIs.qll
|
2023-03-29 22:33:08 -04:00 |
|
Ed Minnix
|
ac8dec740a
|
Refactor UnsafeCertTrustQuery
|
2023-03-29 22:33:08 -04:00 |
|
Ed Minnix
|
a040ff6997
|
Refactor ConditionalBypass
|
2023-03-29 22:33:08 -04:00 |
|
Ed Minnix
|
aa7934161a
|
Refactor CleartextStorage libraries
|
2023-03-29 22:33:08 -04:00 |
|
Ed Minnix
|
b4130e650d
|
Refactor RegexFlowConfigs.qll
|
2023-03-29 22:33:08 -04:00 |
|
Ed Minnix
|
6681c1a3a8
|
Refactor SnakeYaml.qll
|
2023-03-29 22:33:08 -04:00 |
|
Ed Minnix
|
e5f11d00a7
|
Refactor CWE-502/UnsafeDeserialization
|
2023-03-29 22:33:08 -04:00 |
|
Ed Minnix
|
744f2653f0
|
Add QLdoc for RemoteUserInputToArgumentToExecFlow
|
2023-03-29 11:45:09 -04:00 |
|
Ed Minnix
|
25359d2218
|
Deprecate execTainted
|
2023-03-29 11:45:09 -04:00 |
|
Ed Minnix
|
dcd703f1a9
|
Update to the TaintTracking::Global api
|
2023-03-29 11:45:09 -04:00 |
|
Ed Minnix
|
bbf7c67f9b
|
Remove unnecessary private markers (CommandLine and Request forgery)
|
2023-03-29 11:45:09 -04:00 |
|
Ed Minnix
|
0249890747
|
Refactor CommandLineQuery.qll
|
2023-03-29 11:45:09 -04:00 |
|
Edward Minnix III
|
117a983423
|
Merge pull request #12639 from egregius313/egregius313/java/refactor-injection-queries
Java: Refactor injection queries to new dataflow API
|
2023-03-29 11:02:18 -04:00 |
|
Anders Schack-Mulligen
|
d0fa7c7ff8
|
Merge pull request #12683 from aschackmull/java/rangeanalysis-add
Java: Support double-recursive range analysis bounds for addition.
|
2023-03-29 13:39:59 +02:00 |
|
Ed Minnix
|
c8579d8c26
|
RegexInjection docs
|
2023-03-29 07:24:32 -04:00 |
|
Ed Minnix
|
17cdd16c19
|
Fix miscopied isBarrier in JndiInjectionQuery
|
2023-03-29 07:23:13 -04:00 |
|
Jeroen Ketema
|
0acca2ba76
|
Merge pull request #12687 from jketema/unit-2
Make imports of `codeql.util.Unit` private
|
2023-03-29 13:07:12 +02:00 |
|
Edward Minnix III
|
b00104ebe3
|
Merge pull request #12458 from egregius313/egregius313/promote-insecure-ldap-authentication
Java: Promote LDAP Authentication Query
|
2023-03-28 10:39:17 -04:00 |
|
Edward Minnix III
|
97ec808a6f
|
Make configuration public
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com>
|
2023-03-28 10:28:15 -04:00 |
|
Jeroen Ketema
|
3b8ad087eb
|
Make imports of codeql.util.Unit private
|
2023-03-28 14:14:13 +02:00 |
|
Anders Schack-Mulligen
|
d406b051fc
|
Dataflow: Remove accidentally exposed predicates.
|
2023-03-28 10:04:21 +02:00 |
|
Anders Schack-Mulligen
|
b5c66c514e
|
Java: Support double-recursive range analysis bounds for addition.
|
2023-03-28 09:52:05 +02:00 |
|
Ed Minnix
|
9bfb13b942
|
Update to the Global/flow* api
|
2023-03-27 12:26:18 -04:00 |
|
Ed Minnix
|
0eaf222b54
|
Move public classes/predicates to top of library file
|
2023-03-27 12:16:44 -04:00 |
|
Ed Minnix
|
f28f1af5a4
|
Add InsecureLdapUrlSink
|
2023-03-27 12:16:44 -04:00 |
|
Edward Minnix III
|
24d4859149
|
Import changes
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com>
|
2023-03-27 12:16:44 -04:00 |
|
Edward Minnix III
|
151357d02d
|
Make classes/predicates not used outside of query private
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com>
|
2023-03-27 12:16:44 -04:00 |
|
Ed Minnix
|
658c54a18f
|
Change names of configuration to fit new naming convention
|
2023-03-27 12:16:44 -04:00 |
|
Ed Minnix
|
752620a34d
|
Rename SSL configuration and fix PathGraph
|
2023-03-27 12:16:44 -04:00 |
|
Ed Minnix
|
59ce0d7682
|
Documentation changes
|
2023-03-27 12:16:44 -04:00 |
|
Ed Minnix
|
6a0167fa7f
|
Convert to using the new DataFlow modules
|
2023-03-27 12:16:44 -04:00 |
|
Ed Minnix
|
05da1dc4a3
|
Merge concatInsecureLdapString into InsecureLdapUrl constructor
|
2023-03-27 12:16:44 -04:00 |
|
Ed Minnix
|
3936aea690
|
Split Ldap query file into libraries
|
2023-03-27 12:16:43 -04:00 |
|
Jeroen Ketema
|
977f15f8a4
|
Merge pull request #12649 from jketema/unit
Replace all definitions of `Unit` by `import codeql.util.Unit`
|
2023-03-27 08:49:50 +02:00 |
|
Edward Minnix III
|
bb27ba7d3c
|
Merge pull request #12632 from egregius313/egregius313/java/android/refactor-android-query-libraries
Java: Refactor Android `Query.qll` libraries to new dataflow api
|
2023-03-24 11:18:57 -04:00 |
|
Ed Minnix
|
fcd53a8555
|
Deprecate old predicate
|
2023-03-24 10:07:40 -04:00 |
|
Ed Minnix
|
e7bad4cd90
|
Refactor to DataFlow::Global
|
2023-03-24 10:04:46 -04:00 |
|
Ed Minnix
|
899200a9c9
|
Remove unnecessary private markers
|
2023-03-24 09:57:55 -04:00 |
|
Ed Minnix
|
f6b8d89756
|
Refactor GroovyInjectionQuery
|
2023-03-24 09:57:55 -04:00 |
|
Ed Minnix
|
bf5f82bb78
|
Refactor SqlInjectionQuery
|
2023-03-24 09:57:55 -04:00 |
|
Ed Minnix
|
fec80973a9
|
Refactor SpelInjectionQuery
|
2023-03-24 09:57:55 -04:00 |
|
Ed Minnix
|
787b73317d
|
Refactor TemplateInjection
|
2023-03-24 09:57:55 -04:00 |
|
Ed Minnix
|
7e1c42442a
|
Refactor OgnlInjection
|
2023-03-24 09:57:55 -04:00 |
|
Ed Minnix
|
3116e306b1
|
Refactor MvelInjection
|
2023-03-24 09:57:55 -04:00 |
|
Ed Minnix
|
423ab1d9cf
|
Refactor JndiInjection
|
2023-03-24 09:57:54 -04:00 |
|
Ed Minnix
|
8bf3315bb5
|
Refactor JexlInjection
|
2023-03-24 09:57:54 -04:00 |
|
Ed Minnix
|
7ee6c06f7f
|
Refactor RegexInjectionQuery
|
2023-03-24 09:57:54 -04:00 |
|
Ed Minnix
|
c44254e2e0
|
Refactor XsltInjection
|
2023-03-24 09:57:54 -04:00 |
|