Jean Helie
|
daf2743143
|
only use neutral models of kind "sink"
|
2023-06-16 13:58:23 +02:00 |
|
Tony Torralba
|
37a62d3021
|
Merge pull request #13227 from atorralba/atorralba/java/jenkins-generated-models
Java: Add autogenerated models for frameworks related to Jenkins
|
2023-06-14 15:59:28 +02:00 |
|
Tony Torralba
|
7c4cdbf0d6
|
Remove badly generated models
|
2023-06-14 14:20:16 +02:00 |
|
Michael Nebel
|
afec9b05e9
|
Merge pull request #13147 from michaelnebel/csharp/entityframeworkrefactor
C#: Use synthetic global in the EntityFramework code instead of jump steps.
|
2023-06-14 13:47:56 +02:00 |
|
Tony Torralba
|
182513a981
|
Merge pull request #13235 from atorralba/atorralba/java/hudson-models
Java: Add Hudson models
|
2023-06-14 12:33:18 +02:00 |
|
Jean Helie
|
209f3e26d4
|
Merge pull request #13239 from github/tausbn/automodel-application-mode
Java: Add QL support for automodel application mode
|
2023-06-14 11:42:26 +02:00 |
|
Tony Torralba
|
8bafc22add
|
Replace open-url sink kinds with request-forgery
|
2023-06-14 09:59:59 +02:00 |
|
Tony Torralba
|
73d2ab7d66
|
Add change note
|
2023-06-14 09:58:30 +02:00 |
|
Tony Torralba
|
686c35e210
|
Add autogenerated models
|
2023-06-14 09:58:30 +02:00 |
|
Anders Schack-Mulligen
|
1a4fca334f
|
Merge pull request #13273 from aschackmull/dataflow/summarynode-refactor
Dataflow: Refactor FlowSummaryImpl to synthesize nodes independently from DataFlow::Node.
|
2023-06-14 09:38:36 +02:00 |
|
Anders Schack-Mulligen
|
2d616d494e
|
C#/Ruby: Add fields as per review comments.
|
2023-06-13 11:26:30 +02:00 |
|
Jeroen Ketema
|
c3ba206b6a
|
Merge pull request #13346 from jketema/inline-2
Update inline expectation tests to use parameterized module
|
2023-06-13 10:10:55 +02:00 |
|
Anders Schack-Mulligen
|
eec012d308
|
Java: Fix test
|
2023-06-12 13:18:13 +02:00 |
|
Anders Schack-Mulligen
|
97b2bdaa9f
|
Java: Fix types of summary parameter nodes.
|
2023-06-09 15:39:28 +02:00 |
|
Anders Schack-Mulligen
|
254d60c826
|
Dataflow: Refactor FlowSummaryImpl to synthesize nodes independently from DataFlow::Node.
|
2023-06-09 15:27:17 +02:00 |
|
Anders Schack-Mulligen
|
59636c43ca
|
Dataflow: Rename two private predicates.
|
2023-06-09 15:27:17 +02:00 |
|
Stephan Brandauer
|
b38bc52019
|
Java: fix bug in ExcludedFromModeling Characteristic
|
2023-06-09 14:57:56 +02:00 |
|
Anders Schack-Mulligen
|
1b7bbf6320
|
Merge pull request #13083 from aschackmull/dataflow/typestrengthen
Dataflow: Strengthen tracked types.
|
2023-06-09 13:23:30 +02:00 |
|
Jeroen Ketema
|
49993b023e
|
Java: Rewrite inline expectation tests to use parameterized module
|
2023-06-09 10:42:17 +02:00 |
|
Anders Schack-Mulligen
|
44b09507ab
|
Merge pull request #13408 from aschackmull/java/loginjection-perf
Java: Add more negation context to reduce string ops and improve perf.
|
2023-06-09 08:44:27 +02:00 |
|
Anders Schack-Mulligen
|
68f1e40370
|
Java/C#: Add change notes.
|
2023-06-09 08:37:36 +02:00 |
|
Anders Schack-Mulligen
|
85d6b44d92
|
Java: Fix test output.
|
2023-06-09 08:37:36 +02:00 |
|
Anders Schack-Mulligen
|
d230509905
|
Dataflow: Address review comments.
|
2023-06-09 08:37:36 +02:00 |
|
Anders Schack-Mulligen
|
95afd551ff
|
Java: Fix qltest
|
2023-06-09 08:37:36 +02:00 |
|
Anders Schack-Mulligen
|
4399138c82
|
Dataflow: Fix QL4QL alert.
|
2023-06-09 08:37:36 +02:00 |
|
Anders Schack-Mulligen
|
8a584b78ac
|
Dataflow: Enable type strengthening in partial flow.
|
2023-06-09 08:37:36 +02:00 |
|
Anders Schack-Mulligen
|
441ccef6c4
|
Dataflow: Bugfix, use arg type rather than strengthened param type.
|
2023-06-09 08:37:36 +02:00 |
|
Anders Schack-Mulligen
|
a0a9d30286
|
Java: Fix qltests.
|
2023-06-09 08:37:35 +02:00 |
|
Anders Schack-Mulligen
|
4633abe19e
|
Java: Autoformat
|
2023-06-09 08:37:35 +02:00 |
|
Anders Schack-Mulligen
|
ad461a87b4
|
Dataflow: Strengthen tracked types.
|
2023-06-09 08:37:35 +02:00 |
|
Anders Schack-Mulligen
|
1d87f0793b
|
Dataflow: Minor refactor.
|
2023-06-09 08:37:35 +02:00 |
|
Tony Torralba
|
abb775c616
|
Merge pull request #13409 from atorralba/atorralba/java/fix-gson-models
Java: Fix more problems in the Gson models
|
2023-06-08 17:36:40 +02:00 |
|
Tony Torralba
|
4608481d7b
|
Java: Fix more problems in the Gson models
Found during type strengthening work by @aschackmull
|
2023-06-08 14:53:09 +02:00 |
|
Anders Schack-Mulligen
|
5a2ac1b5ca
|
Java: Add more negation context to reduce string ops and improve perf.
|
2023-06-08 14:04:57 +02:00 |
|
Anders Schack-Mulligen
|
dabb4dd643
|
Java: Improve join-order for FunctionalInterface.
|
2023-06-08 13:02:54 +02:00 |
|
Anders Schack-Mulligen
|
cc45db7c76
|
Merge pull request #13394 from atorralba/atorralba/java/fix-gson-jsonarray-models
Java: Fix Gson's JsonArray.add models
|
2023-06-08 11:05:40 +02:00 |
|
Tony Torralba
|
c0135673fa
|
Fix JsonArray.addAll model
Properly test JsonArray.add(String) and JsonArray.addAll(JsonArray) as well
|
2023-06-07 16:18:32 +02:00 |
|
Stephan Brandauer
|
2921df41da
|
Java: fix import
|
2023-06-07 15:22:59 +02:00 |
|
Stephan Brandauer
|
ec3a7e39ad
|
Java: qldoc style
|
2023-06-07 14:57:38 +02:00 |
|
Stephan Brandauer
|
715b1351f3
|
Java: share considerSubtypes predicate between Java modes
|
2023-06-07 14:55:00 +02:00 |
|
Stephan Brandauer
|
7e77e2ea82
|
Java: comment why we're using erased types in MaD
|
2023-06-07 14:42:20 +02:00 |
|
Stephan Brandauer
|
a8799fe981
|
Java: share getCallable interface between automodel extraction modes
|
2023-06-07 14:38:52 +02:00 |
|
Tony Torralba
|
6d7234f8ed
|
Merge pull request #13225 from atorralba/atorralba/java/path-injection-mad-sinks-2
Java: Migrate path injection sinks to models-as-data (simplified)
|
2023-06-07 14:27:36 +02:00 |
|
Tony Torralba
|
35b4c438ff
|
Fix Gson's JsonArray.add models
When the type of the argument isn't JsonElement, the summary must be taint flow instead of value flow
|
2023-06-07 14:12:20 +02:00 |
|
yoff
|
911835c30e
|
Merge pull request #13392 from yoff/java/test-type-tracking-through-flow-summaries
java: test type tracking through flow summaries
|
2023-06-07 14:10:23 +02:00 |
|
Stephan Brandauer
|
92ad02a752
|
Java: update getRelatedLocation qldoc
|
2023-06-07 14:09:07 +02:00 |
|
Stephan Brandauer
|
be6b1d8aaf
|
Java: remove SkipFrameworkModeling characteristic in favour of later evaluation
|
2023-06-07 13:58:56 +02:00 |
|
Stephan Brandauer
|
2e16b71215
|
Java: update qldoc of ClassQualifierCharacteristic
|
2023-06-07 13:52:57 +02:00 |
|
Stephan Brandauer
|
1bfbfec1bc
|
Java: use problem.severity in automodel extraction queries
|
2023-06-07 13:44:52 +02:00 |
|
Erik Krogh Kristensen
|
6ba7f9a238
|
Merge pull request #13352 from erik-krogh/once-again-deps-not-py-cpp
delete old deprecations
|
2023-06-07 13:00:57 +02:00 |
|