Maiky
|
cbb031ee14
|
Update ruby/ql/src/queries/security/cwe-094/TemplateInjection.qhelp
Co-authored-by: intrigus-lgtm <60750685+intrigus-lgtm@users.noreply.github.com>
|
2023-03-08 10:27:39 +01:00 |
|
Maikypedia
|
44997d6b5f
|
Change query id
|
2023-02-25 15:51:04 +01:00 |
|
Maikypedia
|
61fe3704c0
|
Remove unused imports
|
2023-02-25 15:43:48 +01:00 |
|
Maikypedia
|
dd1f7cc1d2
|
Remove missed file
|
2023-02-25 15:35:16 +01:00 |
|
Maikypedia
|
ff50513441
|
Add initial query for Ruby SSTI
|
2023-02-25 15:33:23 +01:00 |
|
github-actions[bot]
|
8eb8daa4d4
|
Post-release preparation for codeql-cli-2.12.3
|
2023-02-16 17:23:25 +00:00 |
|
github-actions[bot]
|
b0315119c6
|
Release preparation for version 2.12.3
|
2023-02-16 11:49:06 +00:00 |
|
Rasmus Wriedt Larsen
|
c72dbc49fc
|
Merge pull request #12165 from RasmusWL/crypto-updates
Python/Ruby/JS Crypto: Add a few algorithms + block modes
|
2023-02-15 14:35:40 +01:00 |
|
Harry Maclean
|
fb14920281
|
Merge pull request #12056 from hmac/test-refactor
|
2023-02-15 17:34:25 +13:00 |
|
Tom Hvitved
|
2113c3c3d9
|
Ruby: Remove NumberUtils.qll
|
2023-02-13 15:59:50 +01:00 |
|
Rasmus Wriedt Larsen
|
39e50f745d
|
Ruby: Fix .expected for CryptoAlgorithms
|
2023-02-13 14:21:12 +01:00 |
|
Anders Schack-Mulligen
|
e877b161d8
|
Merge pull request #12124 from hvitved/dataflow/stage1-dispatch
Data flow: Call context virtual dispatch pruning in stage 1
|
2023-02-13 13:13:43 +01:00 |
|
Arthur Baars
|
457a2bb2a2
|
Merge pull request #12093 from aibaars/oneline-match
Ruby: add support for one-line pattern matches
|
2023-02-13 12:38:28 +01:00 |
|
Erik Krogh Kristensen
|
2f404df17c
|
Merge pull request #10782 from erik-krogh/rbPoly
Ruby: add library input as a source for `rb/polynomial-redos`
|
2023-02-13 12:26:07 +01:00 |
|
Erik Krogh Kristensen
|
26d5fb2412
|
Merge pull request #11824 from erik-krogh/secondMissAnchor
RB: add query detecting validators that use badly anchored regular expressions on library/remote input
|
2023-02-13 11:26:05 +01:00 |
|
erik-krogh
|
634087b417
|
Merge branch 'main' into rbPoly
|
2023-02-13 10:46:00 +01:00 |
|
Rasmus Wriedt Larsen
|
5235964b07
|
sync files
|
2023-02-13 10:44:12 +01:00 |
|
Tom Hvitved
|
0b8173e2e7
|
Ruby: Add another data flow test
|
2023-02-13 09:50:50 +01:00 |
|
Tom Hvitved
|
f7a5a33474
|
Address review comment
|
2023-02-13 09:01:15 +01:00 |
|
Arthur Baars
|
679f02c274
|
Address comments
|
2023-02-10 18:08:30 +01:00 |
|
Arthur Baars
|
07947e6528
|
Address comments
|
2023-02-09 12:02:14 +01:00 |
|
dependabot[bot]
|
bd98ae0dcc
|
build(deps): bump serde_json from 1.0.91 to 1.0.93 in /ruby
Bumps [serde_json](https://github.com/serde-rs/json) from 1.0.91 to 1.0.93.
- [Release notes](https://github.com/serde-rs/json/releases)
- [Commits](https://github.com/serde-rs/json/compare/v1.0.91...v1.0.93)
---
updated-dependencies:
- dependency-name: serde_json
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
|
2023-02-09 08:13:18 +00:00 |
|
Erik Krogh Kristensen
|
3ebac65167
|
apply change-note suggestions from doc review
Co-authored-by: Sam Browning <106113886+sabrowning1@users.noreply.github.com>
|
2023-02-08 14:55:54 +01:00 |
|
Arthur Baars
|
78ad9d67b4
|
Address comments
|
2023-02-08 13:40:46 +01:00 |
|
erik-krogh
|
eb564760be
|
improve qhelp based on doc review
|
2023-02-08 11:00:54 +01:00 |
|
Mathias Vorreiter Pedersen
|
334c41c3e1
|
Merge pull request #12122 from github/post-release-prep/codeql-cli-2.12.2
Post-release preparation for codeql-cli-2.12.2
|
2023-02-07 16:17:57 +00:00 |
|
Tom Hvitved
|
8e8897b08b
|
Data flow: Sync files
|
2023-02-07 15:15:04 +01:00 |
|
Tom Hvitved
|
10534b62c9
|
Data flow: Call context virtual dispatch pruning in stage 1
|
2023-02-07 15:14:27 +01:00 |
|
github-actions[bot]
|
522a892d32
|
Post-release preparation for codeql-cli-2.12.2
|
2023-02-07 13:19:06 +00:00 |
|
Tom Hvitved
|
984729f9b0
|
Merge pull request #12117 from hvitved/ruby/delay-location-to-string
Ruby: Avoid computing `Location::toString` in full
|
2023-02-07 12:42:03 +01:00 |
|
Tom Hvitved
|
c0e3186607
|
Ruby: Avoid computing Location::toString in full
|
2023-02-07 10:06:47 +01:00 |
|
Harry Maclean
|
43ce26e4d0
|
Ruby: re-add Eval.rb
|
2023-02-07 09:37:26 +13:00 |
|
Arthur Baars
|
12f5732782
|
Ruby: downgrade tree-sitter to 0.20.7
The 0.20.9 version caused a stack overflow error on
the mongo-ruby-driver repository.
|
2023-02-06 16:27:51 +01:00 |
|
Mathias Vorreiter Pedersen
|
00fe448e3a
|
Merge pull request #12072 from aschackmull/dataflow/stage3-perf
Dataflow: Fix join in `fwdFlowRead` (take 2)
|
2023-02-06 10:43:11 +00:00 |
|
Arthur Baars
|
e382d6d000
|
Ruby: update stats
|
2023-02-06 10:28:19 +01:00 |
|
Arthur Baars
|
ec46f33a01
|
Ruby: add change note
|
2023-02-06 10:17:19 +01:00 |
|
Arthur Baars
|
f391948b53
|
Ruby: update expected output
|
2023-02-06 10:17:19 +01:00 |
|
Arthur Baars
|
4af0c4bb03
|
Ruby: desugar one-line pattern matches
|
2023-02-06 10:17:19 +01:00 |
|
Arthur Baars
|
3c15fd266d
|
Ruby: add one-line pattern match test
|
2023-02-06 10:17:19 +01:00 |
|
Arthur Baars
|
edbba85b96
|
Ruby: add one-line pattern matches to AST
|
2023-02-06 10:17:18 +01:00 |
|
Arthur Baars
|
e390ca50b0
|
Ruby: upgrade/downgrade scripts
|
2023-02-06 10:17:18 +01:00 |
|
Arthur Baars
|
90c51ef404
|
Ruby: re-generate dbscheme and library
|
2023-02-06 10:17:18 +01:00 |
|
Arthur Baars
|
c554a10e06
|
Ruby: update tree-sitter-ruby
|
2023-02-06 10:17:18 +01:00 |
|
Harry Maclean
|
02b09ca9f7
|
Ruby: Remove unused test files
|
2023-02-04 14:42:59 +13:00 |
|
Harry Maclean
|
cfb3bc9dce
|
Ruby: Remove unused test file
|
2023-02-04 14:30:56 +13:00 |
|
Harry Maclean
|
0711326619
|
Ruby: Move PosixSpawn tests to their own directory
|
2023-02-04 14:30:23 +13:00 |
|
Harry Maclean
|
dbbef0534b
|
Ruby: Move Core tests into core directory
|
2023-02-04 14:28:25 +13:00 |
|
Harry Maclean
|
b5d98d9011
|
Ruby: Move GraphQL test to their own directory
|
2023-02-04 14:25:38 +13:00 |
|
Harry Maclean
|
6c816d5602
|
Ruby: Move ActionDispatch tests to own directory
|
2023-02-04 14:19:08 +13:00 |
|
Harry Maclean
|
58d7af4018
|
Ruby: Move ActionView tests into their own dir
This ensures that changes to unrelated test files don't affect these
tests.
|
2023-02-04 14:19:08 +13:00 |
|