Alex Ford
|
d324f9397c
|
qhelp for rb/csrf-protection-disabled
|
2021-11-04 19:56:56 +00:00 |
|
Alex Ford
|
25da904314
|
test cases for rb/csrf-protection-disabled
|
2021-11-04 19:56:56 +00:00 |
|
Alex Ford
|
4666024419
|
model some ways to configure Rails
|
2021-11-04 19:56:56 +00:00 |
|
Alex Ford
|
91f99ed2a1
|
model skip_forgery_protection calls in ActionController classes
|
2021-11-04 19:56:56 +00:00 |
|
Alex Ford
|
fad7e9489b
|
Add a query to detect instances of CSRF protection being disabled
|
2021-11-04 19:56:55 +00:00 |
|
Alex Ford
|
8a412dc5fd
|
Add CSRFProtectionSetting concept
|
2021-11-04 18:18:29 +00:00 |
|
Ian Wright
|
95f21b5308
|
Merge pull request #7027 from github/z80coder/faster-callee-api-name-feature
more efficient implementation of calleeApiName
|
2021-11-04 14:23:13 +00:00 |
|
Ian Wright
|
b8d7f52d3e
|
format code
|
2021-11-04 12:28:08 +00:00 |
|
Mathias Vorreiter Pedersen
|
58f6058a63
|
Merge pull request #7051 from MathiasVP/better-paths-in-tests
C++: Better `InlineExpectation` tests for path-explanations
|
2021-11-04 11:35:10 +00:00 |
|
Arthur Baars
|
061fc16730
|
Merge pull request #7038 from aibaars/aibaars/merge-3.3-main
Merge rc/3.3 into main
|
2021-11-04 12:23:23 +01:00 |
|
Mathias Vorreiter Pedersen
|
0d1ff4d2ee
|
C++: Respond to review comments and accept test changes.
|
2021-11-04 11:13:23 +00:00 |
|
Arthur Baars
|
27bbddf035
|
Merge pull request #6995 from aibaars/aibaars/pr-qhelp-check
Rewrite qhelp-pr-preview.yml
|
2021-11-04 11:51:14 +01:00 |
|
CodeQL CI
|
2895428d5b
|
Merge pull request #6714 from valeria-meli/javascript/ssrf
Approved by asgerf
|
2021-11-04 03:10:27 -07:00 |
|
CodeQL CI
|
5515256e53
|
Merge pull request #7044 from asgerf/js/proto-pollution-fps
Approved by erik-krogh
|
2021-11-04 02:45:46 -07:00 |
|
Tony Torralba
|
f4704f1325
|
Merge pull request #6397 from atorralba/atorralba/android-intent-redirect-query
Java: Create new Android Intent Redirection query
|
2021-11-04 10:42:59 +01:00 |
|
Tony Torralba
|
fd92c4e435
|
Apply suggestions from code review
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2021-11-04 10:08:53 +01:00 |
|
Mathias Vorreiter Pedersen
|
ae4b6c54bc
|
C++: Change the structure of the 'annotate_path_to_sink' tests to better test path-explanations.
|
2021-11-03 20:32:05 +00:00 |
|
Mathias Vorreiter Pedersen
|
e9b114630a
|
Merge pull request #6948 from ihsinme/ihsinme-patch-076
CPP: Add query for CWE-243 Creation of chroot Jail Without Changing Working Directory
|
2021-11-03 18:50:13 +00:00 |
|
ihsinme
|
aef0275b3c
|
Update IncorrectChangingWorkingDirectory.expected
|
2021-11-03 20:45:38 +03:00 |
|
Arthur Baars
|
7b4460edb7
|
Apply suggestions from code review
Co-authored-by: Aditya Sharad <6874315+adityasharad@users.noreply.github.com>
|
2021-11-03 18:42:49 +01:00 |
|
Tom Hvitved
|
d00196f6be
|
Merge pull request #7048 from hvitved/ruby/remove-node-predicates
Ruby: Remove `Node::getEnclosingCallable` and `ParameterNode::isParameterOf`
|
2021-11-03 17:46:16 +01:00 |
|
ihsinme
|
a9dd868348
|
Update IncorrectChangingWorkingDirectory.qhelp
|
2021-11-03 18:38:30 +03:00 |
|
ihsinme
|
c94b64cbca
|
Update IncorrectChangingWorkingDirectory.qhelp
|
2021-11-03 18:28:57 +03:00 |
|
Tom Hvitved
|
16d96d2ad3
|
Ruby: Remove Node::getEnclosingCallable and ParameterNode::isParameterOf
|
2021-11-03 15:59:29 +01:00 |
|
Arthur Baars
|
b9bf597044
|
Address comments
|
2021-11-03 15:15:36 +01:00 |
|
luciaromeroML
|
e50938588e
|
formatting qll file
|
2021-11-03 10:30:35 -03:00 |
|
Erik Krogh Kristensen
|
3638892d35
|
Merge pull request #6881 from erik-krogh/add-missing-noinline
JS: add pragma[noinline] to predicates where the qldoc mentions join-order
|
2021-11-03 14:21:27 +01:00 |
|
Arthur Baars
|
ddc9ad3187
|
Merge remote-tracking branch 'upstream/rc/3.3' into main
|
2021-11-03 14:01:51 +01:00 |
|
Arthur Baars
|
1327d7c8d5
|
Merge pull request #7043 from aibaars/fix-ql-tests-3.3
Ruby: Fix QL tests and Rust compilation error
|
2021-11-03 13:59:29 +01:00 |
|
Asger Feldthaus
|
712614a03c
|
JS: Block prototype pollution flow into this
|
2021-11-03 13:33:50 +01:00 |
|
Asger Feldthaus
|
08bc80ffdb
|
JS: Block prototype pollution assignment flows through .replace()
|
2021-11-03 13:24:29 +01:00 |
|
Asger Feldthaus
|
76e841830f
|
JS: Check for labeled barriers in reachableFromInput
|
2021-11-03 13:10:20 +01:00 |
|
Arthur Baars
|
aab8c64973
|
Ruby: fix compilation error
|
2021-11-03 12:32:45 +01:00 |
|
Arthur Baars
|
2c5d5ecdd8
|
Ruby: QLTest: fix pack search path for upgrades
|
2021-11-03 12:14:58 +01:00 |
|
Arthur Baars
|
32765e9bc1
|
Ruby: trigger jobs on workflow change
|
2021-11-03 12:14:58 +01:00 |
|
Tom Hvitved
|
ab37ae6613
|
Merge pull request #7036 from hvitved/ruby/truncate-get-value-text
Ruby: Truncate concatenated strings in `getValueText`
|
2021-11-03 10:57:43 +01:00 |
|
ihsinme
|
c175f0aa9d
|
Update IncorrectChangingWorkingDirectory.ql
|
2021-11-03 12:25:30 +03:00 |
|
Anders Schack-Mulligen
|
e6145f04d2
|
Merge pull request #6966 from atorralba/atorralba/android-explicit-intent-sanitizer
Android: Add ExplicitIntentSanitizer and allowIntentExtrasImplicitRead
|
2021-11-03 10:20:09 +01:00 |
|
Erik Krogh Kristensen
|
ab4780c505
|
Merge pull request #7032 from erik-krogh/cwe497
JS: add CWE-497 to js/stack-trace-exposure
|
2021-11-03 08:55:49 +01:00 |
|
Mathias Vorreiter Pedersen
|
4a2894a707
|
Merge pull request #7025 from MathiasVP/nomagic-parameterCand
Dataflow: Replace a 'noinline' pragma with a 'nomagic' pragma
|
2021-11-02 20:40:44 +00:00 |
|
Arthur Baars
|
eb645ba963
|
Merge remote-tracking branch 'origin/rc/3.3' into 'main'
|
2021-11-02 21:10:41 +01:00 |
|
Tom Hvitved
|
8b287a7846
|
Ruby: Truncate concatenated strings in getValueText
|
2021-11-02 18:19:49 +01:00 |
|
Erik Krogh Kristensen
|
9d99ce12c4
|
add CWE-497 to js/stack-trace-exposure
|
2021-11-02 15:43:55 +01:00 |
|
Dave Bartolomeo
|
d828ab7fd2
|
Merge pull request #6955 from github/codeql-ruby-3.3
RC 3.3: merge codeql-ruby repository into github/codeql
|
2021-11-02 09:57:49 -04:00 |
|
yoff
|
97625d7c2c
|
Merge pull request #7023 from RasmusWL/toml
Python: Add modeling of `toml`
|
2021-11-02 14:42:06 +01:00 |
|
ihsinme
|
62b3c3c9a0
|
Update IncorrectChangingWorkingDirectory.ql
|
2021-11-02 16:16:17 +03:00 |
|
yoff
|
0240631510
|
Merge pull request #6782 from RasmusWL/fastapi
Python: Model FastAPI
|
2021-11-02 14:16:12 +01:00 |
|
ihsinme
|
738354b8e7
|
Update cpp/ql/src/experimental/Security/CWE/CWE-243/IncorrectChangingWorkingDirectory.ql
Co-authored-by: Mathias Vorreiter Pedersen <mathiasvp@github.com>
|
2021-11-02 16:13:34 +03:00 |
|
Rasmus Wriedt Larsen
|
c52e453342
|
Python: Minor rewrite
|
2021-11-02 13:37:50 +01:00 |
|
Erik Krogh Kristensen
|
54fba2d6a1
|
Merge pull request #6781 from erik-krogh/ldap
JS: Move LDAP injection out of experimental
|
2021-11-02 13:35:32 +01:00 |
|