Esben Sparre Andreasen
|
cb30329b3d
|
JS: make DynamicPropertyAccess.qll from PrototypePollutionUtility.ql
|
2020-02-07 13:57:52 +01:00 |
|
Shati Patel
|
4cbf7d2a6d
|
Merge pull request #2789 from jf205/codeql-178
QL language handbook: add link to information about module resolution in QL spec
|
2020-02-07 12:27:02 +01:00 |
|
Calum Grant
|
389e6266d9
|
Merge pull request #2773 from hvitved/csharp/useless-assignment-to-local-default
C#: Remove false positives for `cs/useless-assignment-to-local`
|
2020-02-07 10:37:19 +00:00 |
|
james
|
f2320bbe56
|
docs: add link to module resolution in ql spec
|
2020-02-07 10:26:31 +00:00 |
|
Jonas Jensen
|
19286bd82a
|
Merge pull request #2765 from MathiasVP/ir-gvn-ast-wrapper-fixup
C++: Make AST GVN a wrapper for IR-based GVN
|
2020-02-07 08:49:15 +01:00 |
|
semmle-qlci
|
e05dd352ad
|
Merge pull request #2768 from asger-semmle/js/protopol-packages
Approved by esbena
|
2020-02-07 07:21:04 +00:00 |
|
yo-h
|
9c3fed7550
|
Merge pull request #2734 from aschackmull/java/taint-postupdate
Java: Improve taint step modeling to use postupdate nodes.
|
2020-02-06 21:17:55 -05:00 |
|
Robert Marsh
|
dac4f0fac0
|
Merge pull request #2763 from jbj/ir-VariableNode
C++: DefaultTaintTracking perf fix for globals
|
2020-02-06 18:54:14 -05:00 |
|
Mathias Vorreiter Pedersen
|
538c2b205d
|
C++: Accept output
|
2020-02-06 18:44:08 +01:00 |
|
Asger Feldthaus
|
91a5385e7f
|
JS: Add libraries to change note
|
2020-02-06 14:59:52 +00:00 |
|
Asger Feldthaus
|
a628f787e8
|
JS: Fix qldoc comment
|
2020-02-06 14:59:52 +00:00 |
|
Asger Feldthaus
|
f84af74d1d
|
JS: Handle more libraries
|
2020-02-06 14:59:52 +00:00 |
|
Asger Feldthaus
|
c559ab13e7
|
JS: Add test and handle parameter with source object
|
2020-02-06 14:59:52 +00:00 |
|
Asger Feldthaus
|
34a9dce33d
|
JS: Detect property enumeration through for-own
|
2020-02-06 14:59:52 +00:00 |
|
Asger Feldthaus
|
418f841749
|
JS: Handle imports through lazy-cache
|
2020-02-06 14:59:52 +00:00 |
|
semmle-qlci
|
180e9d4731
|
Merge pull request #2779 from asger-semmle/js/protopol-regression-fix
Approved by esbena
|
2020-02-06 14:58:19 +00:00 |
|
Mathias Vorreiter Pedersen
|
2017ca8154
|
C++/C#: Sync identical files
|
2020-02-06 15:53:23 +01:00 |
|
Mathias Vorreiter Pedersen
|
f02513e376
|
C++: Exclude UnknownLocation results from getLocation if there is a location that's known
|
2020-02-06 15:53:22 +01:00 |
|
Mathias Vorreiter Pedersen
|
23ca363b87
|
C++: Formatting
|
2020-02-06 15:53:22 +01:00 |
|
Mathias Vorreiter Pedersen
|
98969e3bf9
|
C++: Accepted ir_gvn output after toString change
|
2020-02-06 15:53:22 +01:00 |
|
Mathias Vorreiter Pedersen
|
0d181a7101
|
C++: Add tests and accept output
|
2020-02-06 15:48:08 +01:00 |
|
Mathias Vorreiter Pedersen
|
69e085dda7
|
C++: Add getDebugString predicate and use it in ValueNumberPropertyProvider
|
2020-02-06 15:43:57 +01:00 |
|
Mathias Vorreiter Pedersen
|
ef89e3bdb5
|
C++: Added charpred to ensure that only instructions that have a source representation have a GVN
|
2020-02-06 15:43:57 +01:00 |
|
Mathias Vorreiter Pedersen
|
63f1d3ded7
|
C++: Replace rank[1] with min
|
2020-02-06 15:43:57 +01:00 |
|
Mathias Vorreiter Pedersen
|
2303dac0b7
|
C++: Implemented getKind to new GVN class and added predicates for obtaining expressions from a GVN
|
2020-02-06 15:43:57 +01:00 |
|
Mathias Vorreiter Pedersen
|
8041804bac
|
C#: Include TValueNumber in internal files
|
2020-02-06 15:39:27 +01:00 |
|
Robert Marsh
|
2f91778e7e
|
C++: add IR-based wrapper for value numbering
|
2020-02-06 15:35:20 +01:00 |
|
Robert Marsh
|
ffaaed0550
|
C++: separate IR ValueNumber newtype and interface
|
2020-02-06 15:35:20 +01:00 |
|
Jonas Jensen
|
4997aa7428
|
Merge pull request #2772 from MathiasVP/more-gvn-loads
C++: Better value numbering support for loading fields in IR
|
2020-02-06 14:15:27 +01:00 |
|
Jonas Jensen
|
2e883ab4b2
|
Merge pull request #2760 from geoffw0/defaulttainttest3
C++: Emulate old security library's use of predictable more accurately.
|
2020-02-06 13:47:27 +01:00 |
|
semmle-qlci
|
75bdf42850
|
Merge pull request #2770 from asger-semmle/js/update-extractor-version-string
Approved by erik-krogh
|
2020-02-06 12:41:46 +00:00 |
|
Anders Schack-Mulligen
|
aa8ebf4fe1
|
Merge pull request #2764 from JLLeitschuh/patch-1
Add DefaultFullHttpResponse to Netty Check
|
2020-02-06 12:19:04 +01:00 |
|
Asger Feldthaus
|
0345c48503
|
JS: Bump extractor version string
|
2020-02-06 11:04:59 +00:00 |
|
Mathias Vorreiter Pedersen
|
19e1d82708
|
Merge pull request #2686 from jbj/ir-crement-load
C++: Move the LoadInstruction from `++` to `e` in `e++`.
|
2020-02-06 11:53:55 +01:00 |
|
Asger Feldthaus
|
38ef07ce73
|
JS: Fix join ordering
|
2020-02-06 10:29:05 +00:00 |
|
Mathias Vorreiter Pedersen
|
aaa6233a99
|
C++/C#: Sync identical files
|
2020-02-06 11:24:07 +01:00 |
|
Mathias Vorreiter Pedersen
|
527181bb6f
|
C++: Rename CongruentCopyInstructionTotal to LoadTotalOverlapInstruction and extend LoadInstruction instead of CopyInstruction
|
2020-02-06 11:23:42 +01:00 |
|
Geoffrey White
|
2dfeafac30
|
C++: Interaction with another PR.
|
2020-02-06 10:21:55 +00:00 |
|
semmle-qlci
|
90f94e2e54
|
Merge pull request #2777 from erik-krogh/TaintedPathTests
Approved by esbena
|
2020-02-06 10:18:24 +00:00 |
|
Geoffrey White
|
851c1134f3
|
C++: Add 'strlen' back.
|
2020-02-06 10:17:37 +00:00 |
|
Geoffrey White
|
860d0aa42f
|
C++: Remove single argument functions.
|
2020-02-06 10:17:37 +00:00 |
|
Geoffrey White
|
539d6716f5
|
C++: Remove commented entries.
|
2020-02-06 10:17:37 +00:00 |
|
Geoffrey White
|
d54d7e8410
|
C++: Post-merge fix.
|
2020-02-06 10:17:37 +00:00 |
|
Geoffrey White
|
2fddb09a30
|
C++: New autoformat.
|
2020-02-06 10:17:37 +00:00 |
|
Geoffrey White
|
95c77ca3c6
|
C++: Update comment.
|
2020-02-06 10:17:37 +00:00 |
|
Geoffrey White
|
9c05ffeb3a
|
C++: Emulate old security library's use of predictable more accurately.
|
2020-02-06 10:17:37 +00:00 |
|
Anders Schack-Mulligen
|
75f7671e75
|
Java: Fix .expected
|
2020-02-06 10:27:44 +01:00 |
|
Mathias Vorreiter Pedersen
|
f4bbdee6c2
|
Merge pull request #2745 from Cornelius-Riemenschneider/cpp-range-analysis
C++: Fix bug in range analysis.
|
2020-02-06 10:10:06 +01:00 |
|
Erik Krogh Kristensen
|
d8a30c48a3
|
update expected output of TaintedPath tests
|
2020-02-06 09:47:15 +01:00 |
|
Mathias Vorreiter Pedersen
|
ba395cf11a
|
C++: Update test annotations and accept output
|
2020-02-06 09:26:33 +01:00 |
|