Erik Krogh Kristensen
|
240248b9cf
|
Merge pull request #11453 from erik-krogh/unsafeHtmlConstruction
RB: add unsafe-html-construction query
|
2023-01-23 16:40:25 +01:00 |
|
Erik Krogh Kristensen
|
5be97f3761
|
Merge pull request #11909 from erik-krogh/concatCode
Rb: recognize string concatenations as sinks for unsafe-code-construction
|
2023-01-23 16:22:46 +01:00 |
|
erik-krogh
|
ae00518ddf
|
remove the isAdditionalTaintStep predicate from UnsafeHtmlConstructionQuery, as it was not needed
|
2023-01-23 15:27:19 +01:00 |
|
erik-krogh
|
7c6ee5f293
|
Merge branch 'main' into unsafeHtmlConstruction
|
2023-01-23 15:01:01 +01:00 |
|
Erik Krogh Kristensen
|
32c4cf5769
|
Apply suggestions from code review
Co-authored-by: Alex Ford <alexrford@users.noreply.github.com>
|
2023-01-23 14:58:04 +01:00 |
|
Alex Ford
|
55550e7980
|
Merge pull request #11941 from alexrford/summary-component-tostring-syntheticglobal
Add missing toString case for synthetic globals
|
2023-01-23 10:00:00 +00:00 |
|
Arthur Baars
|
99148244a4
|
Merge pull request #11856 from aibaars/update-grammars
Update grammars
|
2023-01-23 09:46:50 +01:00 |
|
Michael Nebel
|
69a42d8b1f
|
Merge pull request #11931 from michaelnebel/csharp/refactor
Remove the Csv postfix of some predicate names.
|
2023-01-23 09:09:48 +01:00 |
|
github-actions[bot]
|
b62cb6ba84
|
Post-release preparation for codeql-cli-2.12.1
|
2023-01-20 19:49:56 +00:00 |
|
Alex Ford
|
e4df1f5a6f
|
Ruby: add missing toString case for synthetic globals
|
2023-01-20 13:31:43 +00:00 |
|
github-actions[bot]
|
005b3e4a47
|
Release preparation for version 2.12.1
|
2023-01-20 12:03:19 +00:00 |
|
Michael Nebel
|
dc223cb82e
|
Sync files and make corresponding changes for other languages.
|
2023-01-19 15:14:06 +01:00 |
|
Erik Krogh Kristensen
|
ee9b01b5e6
|
Apply suggestions from code review
Co-authored-by: Alex Ford <alexrford@users.noreply.github.com>
|
2023-01-18 22:14:46 +01:00 |
|
erik-krogh
|
8251ad5e99
|
add unsafe-html-construction query
|
2023-01-17 15:35:17 +01:00 |
|
erik-krogh
|
8715790fe7
|
add explicit this
|
2023-01-17 15:17:48 +01:00 |
|
erik-krogh
|
a562568522
|
add string concat as a sink for command-construction
|
2023-01-17 14:48:09 +01:00 |
|
erik-krogh
|
9d9de18bc9
|
add a generalized AddExprRoot into Operation.qll
|
2023-01-17 14:48:08 +01:00 |
|
erik-krogh
|
8fc3b268e8
|
add string concat as a sink for code-construction
|
2023-01-17 14:48:06 +01:00 |
|
Rasmus Wriedt Larsen
|
a0b1c2ea79
|
DataFlow: Add uniqueParameterNodePositionExclude
|
2023-01-17 14:05:22 +01:00 |
|
Rasmus Wriedt Larsen
|
2b0a5fd5d1
|
DataFlow: Add uniqueParameterNodeAtPositionExclude
|
2023-01-17 14:05:17 +01:00 |
|
Erik Krogh Kristensen
|
59a8b21851
|
Merge pull request #10862 from erik-krogh/unsafeCodeConstruction
Rb: Add an `unsafe-code-construction` query
|
2023-01-16 13:22:58 +01:00 |
|
Arthur Baars
|
dc6f5f60d1
|
Ruby: update stats
|
2023-01-13 10:22:42 +01:00 |
|
Arthur Baars
|
28c9b52dce
|
Ruby: add change note
|
2023-01-13 10:22:42 +01:00 |
|
Arthur Baars
|
46063c7d04
|
Ruby: update expected output
|
2023-01-13 10:22:41 +01:00 |
|
Arthur Baars
|
c4ec674057
|
Ruby: support anonymous (hash)splat parameters/arguments
|
2023-01-13 10:22:41 +01:00 |
|
Arthur Baars
|
4d3e2bb814
|
Ruby: upgrade/downgrade scripts
|
2023-01-13 10:22:41 +01:00 |
|
Arthur Baars
|
290167e1a3
|
Ruby: re-generated dbscheme/library
|
2023-01-13 10:22:41 +01:00 |
|
Michael Nebel
|
18a815ca8b
|
Merge pull request #11721 from michaelnebel/csharpjava/refactorprovenance
C#/Java: Re-factor provenance related predicates.
|
2023-01-12 10:50:31 +01:00 |
|
Pierre
|
c3116b3f0f
|
Merge branch 'main' into turbo/experimental/combined
|
2023-01-11 18:02:55 +01:00 |
|
Michael Nebel
|
7e4f7a0c17
|
C#: Address review comments and sync files.
|
2023-01-11 16:29:24 +01:00 |
|
Michael Nebel
|
67cbe38255
|
Sync files.
|
2023-01-11 16:20:55 +01:00 |
|
Michael Nebel
|
c01361a1fd
|
Ruby: Re-factor provenance related predicates for summarized callable.
|
2023-01-11 16:20:55 +01:00 |
|
Michael Nebel
|
ea173f9516
|
Sync files.
|
2023-01-11 16:20:55 +01:00 |
|
Tony Torralba
|
c9d1cd97fb
|
Ruby: Remove omittable exists variables
|
2023-01-10 13:39:49 +01:00 |
|
Erik Krogh Kristensen
|
f2658a0936
|
apply suggestions from doc review
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
|
2023-01-10 12:56:22 +01:00 |
|
Erik Krogh Kristensen
|
5157d4df7b
|
Merge pull request #11581 from erik-krogh/stdin
Rb: add stdin as source for unsafe-deserialization
|
2023-01-09 13:57:47 +01:00 |
|
yoff
|
c01ce955ba
|
Merge pull request #11778 from yoff/shared/inline-tests
Shared: Inline test expectations
|
2023-01-09 13:21:18 +01:00 |
|
Harry Maclean
|
5b117084db
|
Merge pull request #11534 from hmac/array-inclusion-barrier-guard-constant
Ruby: Make array inclusion barrier more sensitive
|
2023-01-09 20:57:09 +13:00 |
|
github-actions[bot]
|
cdb8f67601
|
Post-release preparation for codeql-cli-2.12.0
|
2023-01-06 10:36:34 +00:00 |
|
erik-krogh
|
0a1769657d
|
add change-note
|
2023-01-06 09:09:09 +01:00 |
|
erik-krogh
|
19d2b49562
|
drive-by: make Base64.decode64(..) into a flowsummary that is shared with all queries
|
2023-01-06 09:04:37 +01:00 |
|
erik-krogh
|
1a27441cfb
|
drive-by: delete code-execution sinks from unsafe-deserialization, we risked duplicate alerts
|
2023-01-06 09:04:36 +01:00 |
|
erik-krogh
|
0e6028a7f3
|
add stdin as source for unsafe-deserialization
|
2023-01-06 09:04:36 +01:00 |
|
erik-krogh
|
f98ff65b11
|
use eval() instead of send() in test
|
2023-01-05 20:04:04 +01:00 |
|
Erik Krogh Kristensen
|
d9176541c6
|
Apply suggestions from code review
Co-authored-by: Alex Ford <alexrford@users.noreply.github.com>
|
2023-01-05 20:02:54 +01:00 |
|
Jeroen Ketema
|
de37f3b7d5
|
Properly indent code block in change log
|
2023-01-05 18:38:33 +01:00 |
|
Jeroen Ketema
|
170242f79c
|
Apply suggestions from code review
|
2023-01-05 17:57:19 +01:00 |
|
Nick Rolfe
|
6e07076151
|
tweak wording in 2.12 release notes
|
2023-01-05 16:46:44 +00:00 |
|
github-actions[bot]
|
b6a8193785
|
Release preparation for version 2.12.0
|
2023-01-05 16:32:14 +00:00 |
|
Rasmus Lerchedahl Petersen
|
c3b3c05cf3
|
Revert "Merge pull request #37 from erik-krogh/shared/inline-tests"
This reverts commit 65fe9abcfe, reversing
changes made to 08e9d3391f.
|
2023-01-05 09:19:43 +01:00 |
|