Jonas Jensen
|
ac89559b20
|
Merge pull request #3744 from github/p0-patch-1
Fix typo in cpp-security-extended.qls
|
2020-06-19 21:19:20 +02:00 |
|
Pavel Avgustinov
|
00f1e57d0c
|
Update cpp-security-extended.qls
|
2020-06-19 20:16:24 +01:00 |
|
Jonas Jensen
|
81d8dc15cd
|
Merge pull request #3693 from geoffw0/stringtest
C++: Add tests of char* -> std::string -> char* conversions.
|
2020-06-19 21:12:33 +02:00 |
|
Taus Brock-Nannestad
|
410f4781b3
|
Python: Fix one last reference.
This one got lost in the big renaming somehow.
|
2020-06-19 20:15:01 +02:00 |
|
semmle-qlci
|
1548eca994
|
Merge pull request #3689 from erik-krogh/https-fix
Approved by mchammer01
|
2020-06-19 17:00:11 +01:00 |
|
Tom Hvitved
|
573d55a160
|
Merge pull request #3740 from github/codeql-analysis-yml
Enable code scanning
|
2020-06-19 17:57:52 +02:00 |
|
Taus Brock-Nannestad
|
48e3e9c0b4
|
Python: Do all the renames.
|
2020-06-19 17:02:47 +02:00 |
|
james
|
f02b54fcd2
|
docs: add more detailed qldoc style guide
|
2020-06-19 15:59:22 +01:00 |
|
Taus Brock-Nannestad
|
06d6913a20
|
Python: Change "sanity" to "consistency".
|
2020-06-19 16:55:59 +02:00 |
|
Taus Brock-Nannestad
|
01fb1e3786
|
Python: Get rid of deprecated terms in code and .qhelp.
|
2020-06-19 16:51:09 +02:00 |
|
Taus
|
2081d0cecc
|
Merge pull request #3575 from RasmusWL/python-add-qldoc-FunctionValue.getQualifiedName
Python: Add QLDoc for FunctionValue.getQualifiedName
|
2020-06-19 16:32:23 +02:00 |
|
Tom Hvitved
|
56670f3a5f
|
Disable analysis for JS and Python
|
2020-06-19 16:25:23 +02:00 |
|
Jonas Jensen
|
09d7ed092b
|
Merge pull request #3612 from dbartol/github/codeql-c-analysis-team/69_union
C++: Share `TInstruction` across IR stages
|
2020-06-19 16:03:11 +02:00 |
|
Erik Krogh Kristensen
|
0f5ef2c02a
|
Merge branch 'js-team-sprint' into https-fix
|
2020-06-19 14:57:44 +02:00 |
|
semmle-qlci
|
e13353f26a
|
Merge pull request #3732 from erik-krogh/priv-file-polish
Approved by mchammer01
|
2020-06-19 13:56:57 +01:00 |
|
Tom Hvitved
|
4b47483263
|
Add codeql-config.yml
|
2020-06-19 12:28:52 +00:00 |
|
Erik Krogh Kristensen
|
e46bd709c4
|
add change note
|
2020-06-19 14:15:50 +02:00 |
|
Erik Krogh Kristensen
|
0ee3f4977c
|
add test of webpack-dev-server and monorepo import
|
2020-06-19 14:15:46 +02:00 |
|
Erik Krogh Kristensen
|
c860151e8d
|
recognize instances of express from webpack-dev-server
|
2020-06-19 14:15:25 +02:00 |
|
Erik Krogh Kristensen
|
11cc97d286
|
add basic support for importing from neighbouring packages
|
2020-06-19 14:15:10 +02:00 |
|
Erik Krogh Kristensen
|
a17d152ca4
|
Merge branch 'js-team-sprint' into priv-file-polish
|
2020-06-19 13:19:10 +02:00 |
|
semmle-qlci
|
bfb2e9d6ea
|
Merge pull request #3724 from erik-krogh/bad-random-polish
Approved by mchammer01
|
2020-06-19 12:18:25 +01:00 |
|
Tom Hvitved
|
ffe3f500d7
|
Restrict languages in codeql-analysis.yml
|
2020-06-19 13:01:28 +02:00 |
|
Esben Sparre Andreasen
|
457588e893
|
JS: mention MITM
|
2020-06-19 11:59:12 +02:00 |
|
Anders Schack-Mulligen
|
8107fbadc2
|
Merge pull request #3456 from hvitved/dataflow/precise-field-types
Data flow: Track precise types during field flow
|
2020-06-19 11:50:10 +02:00 |
|
Esben Sparre Andreasen
|
4126d5b59e
|
Merge pull request #3646 from dellalibera/master
[javascript] CodeQL query to detect missing origin validation in cross-origin communication via postMessage
|
2020-06-19 11:43:57 +02:00 |
|
Tom Hvitved
|
a285f6460c
|
Create codeql-analysis.yml
|
2020-06-19 11:34:31 +02:00 |
|
Tom Hvitved
|
ca86bb8603
|
Address review comments
|
2020-06-19 10:34:11 +02:00 |
|
Esben Sparre Andreasen
|
0463c427a5
|
Update javascript/ql/src/Security/CWE-770/ResourceExhaustion.qhelp
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
|
2020-06-19 09:47:59 +02:00 |
|
Esben Sparre Andreasen
|
b8229ca362
|
Update javascript/ql/src/Security/CWE-770/ResourceExhaustion.qhelp
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
|
2020-06-19 09:47:48 +02:00 |
|
Esben Sparre Andreasen
|
e73beccc0b
|
Update javascript/ql/src/Security/CWE-770/ResourceExhaustion.qhelp
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
|
2020-06-19 09:47:26 +02:00 |
|
Esben Sparre Andreasen
|
2846666f32
|
Update javascript/ql/src/Security/CWE-770/ResourceExhaustion.qhelp
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
|
2020-06-19 09:47:13 +02:00 |
|
Esben Sparre Andreasen
|
4557af3c30
|
Update javascript/ql/src/Security/CWE-770/ResourceExhaustion.qhelp
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
|
2020-06-19 09:46:58 +02:00 |
|
Esben Sparre Andreasen
|
baaa31665a
|
Update javascript/ql/src/experimental/Security/CWE-020/PostMessageNoOriginCheck.qhelp
|
2020-06-19 09:05:13 +02:00 |
|
Alessio Della Libera
|
eba64dba7c
|
Update javascript/ql/src/experimental/Security/CWE-020/PostMessageNoOriginCheck.ql
Co-authored-by: Esben Sparre Andreasen <esbena@github.com>
|
2020-06-18 19:44:46 +02:00 |
|
Alessio Della Libera
|
c0271b1627
|
Update javascript/ql/src/experimental/Security/CWE-020/PostMessageNoOriginCheck.qhelp
Co-authored-by: Esben Sparre Andreasen <esbena@github.com>
|
2020-06-18 19:44:38 +02:00 |
|
Alessio Della Libera
|
ffc9a449ab
|
Update javascript/ql/src/experimental/Security/CWE-020/PostMessageNoOriginCheck.qhelp
Co-authored-by: Esben Sparre Andreasen <esbena@github.com>
|
2020-06-18 19:43:45 +02:00 |
|
Alessio Della Libera
|
e84339d5bf
|
Update javascript/ql/src/experimental/Security/CWE-020/PostMessageNoOriginCheck.qhelp
Co-authored-by: Esben Sparre Andreasen <esbena@github.com>
|
2020-06-18 19:43:36 +02:00 |
|
ubuntu
|
71a7ec593c
|
Use StringOps to identify functions used for verifing the origin
|
2020-06-18 19:41:07 +02:00 |
|
Erik Krogh Kristensen
|
7d6dac479c
|
Merge branch 'js-team-sprint' into https-fix
|
2020-06-18 16:53:01 +02:00 |
|
Erik Krogh Kristensen
|
dcf617b235
|
Merge branch 'js-team-sprint' into bad-random-polish
|
2020-06-18 16:52:32 +02:00 |
|
Erik Krogh Kristensen
|
6b0adf18d1
|
rewrite sentence in private-file-exposure qhelp
|
2020-06-18 16:51:15 +02:00 |
|
Erik Krogh Kristensen
|
1556b62007
|
Merge branch 'js-team-sprint' into priv-file-polish
|
2020-06-18 16:40:53 +02:00 |
|
Erik Krogh Kristensen
|
9ba2c98ec0
|
Apply suggestions from doc review
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
|
2020-06-18 16:38:52 +02:00 |
|
semmle-qlci
|
20e96799e2
|
Merge pull request #3661 from erik-krogh/build-leaks
Approved by asgerf, mchammer01
|
2020-06-18 15:32:45 +01:00 |
|
Taus
|
44637e29ee
|
Merge pull request #3716 from RasmusWL/python-fix-re-escape-fp
Python: Fix FP in treating re.escape as regex
|
2020-06-18 16:05:50 +02:00 |
|
Marcono1234
|
161ba92123
|
Simplify NoAssignInBooleanExprs.ql
|
2020-06-18 15:16:09 +02:00 |
|
Esben Sparre Andreasen
|
ab01dda559
|
JS: another qhelp fixup
|
2020-06-18 13:01:02 +02:00 |
|
Esben Sparre Andreasen
|
c9f60d4c97
|
JS: add lodash sinks for js/resource-exhaustion
|
2020-06-18 13:01:02 +02:00 |
|
Esben Sparre Andreasen
|
96160a6334
|
JS: fixup qhelp
|
2020-06-18 13:01:02 +02:00 |
|