Joe Farebrother
|
df74a142dd
|
Update for collection flow and add more tests
|
2021-07-15 10:33:33 +01:00 |
|
Joe Farebrother
|
8f89d748fe
|
Add spring tests
|
2021-07-15 10:33:33 +01:00 |
|
Joe Farebrother
|
4be7e94dcc
|
Add more spring stubs
|
2021-07-15 10:33:30 +01:00 |
|
Joe Farebrother
|
c1555b36a1
|
Add additional HTTP flow steps
|
2021-07-15 10:32:13 +01:00 |
|
Joe Farebrother
|
9b6213dbf0
|
Convert existing spring http steps to csv
|
2021-07-15 10:32:10 +01:00 |
|
Erik Krogh Kristensen
|
5ff7d208b7
|
add taint step through arrify
|
2021-07-15 11:24:50 +02:00 |
|
Erik Krogh Kristensen
|
e64f29fe8f
|
add support for Array.prototype.find and polyfills
|
2021-07-15 11:16:06 +02:00 |
|
Erik Krogh Kristensen
|
f6f63e2811
|
add model for the array-from polyfill
|
2021-07-15 10:51:55 +02:00 |
|
Anders Schack-Mulligen
|
d34e748c83
|
Merge pull request #6290 from aschackmull/java/query-metadata3
Java: Add metadata.
|
2021-07-15 09:59:45 +02:00 |
|
Anders Schack-Mulligen
|
60b3dbd217
|
Java: Add metadata.
|
2021-07-15 09:16:56 +02:00 |
|
Anders Schack-Mulligen
|
bf0877c5cb
|
Merge pull request #6289 from github/workflow/coverage/update
Update CSV framework coverage reports
|
2021-07-15 09:15:51 +02:00 |
|
Anders Schack-Mulligen
|
e18a20fedb
|
Merge pull request #6285 from smowton/smowton/feature/spring-jdbc-object
Add models for org.springframework.jdbc.object
|
2021-07-15 09:06:56 +02:00 |
|
Robert Marsh
|
4d8e882214
|
Merge pull request #6186 from geoffw0/formatarg
C++: Fix FPs from cpp/wrong-type-format-argument
|
2021-07-14 17:20:46 -07:00 |
|
github-actions[bot]
|
d6186e8d0f
|
Add changed framework coverage reports
|
2021-07-15 00:06:37 +00:00 |
|
Erik Krogh Kristensen
|
22dfe84ee8
|
add xss sink for react-tooltip
|
2021-07-14 20:03:50 +02:00 |
|
Erik Krogh Kristensen
|
14b26f2a68
|
add mkdirp as a sink for tainted-path
|
2021-07-14 19:32:22 +02:00 |
|
Chris Smowton
|
f2b232f276
|
Add change note
|
2021-07-14 17:39:58 +01:00 |
|
Chris Smowton
|
0b2750828e
|
Add models for org.springframework.jdbc.object
Also add tests for the existing Spring JDBC SQL injection sinks in the process
|
2021-07-14 17:25:00 +01:00 |
|
Taus
|
fb57c5f6f0
|
Merge pull request #6143 from RasmusWL/concepts-private-import-python
Python: Make `import python` private in Concepts.qll
|
2021-07-14 17:49:06 +02:00 |
|
Taus
|
5c5ee85332
|
Merge pull request #6122 from RasmusWL/mention-mysqlclient
Python: Mention modeling of `mysqlclient` PyPI package
|
2021-07-14 17:48:40 +02:00 |
|
Taus
|
30d61045d2
|
Python: Mention nameIndicatesSensitiveData
Co-authored-by: Rasmus Wriedt Larsen <rasmuswriedtlarsen@gmail.com>
|
2021-07-14 17:33:39 +02:00 |
|
Erik Krogh Kristensen
|
f462c9bb76
|
add taint through the parseqs library
|
2021-07-14 17:22:35 +02:00 |
|
Erik Krogh Kristensen
|
bec1818fc7
|
add taint through the normalize-url library
|
2021-07-14 17:15:14 +02:00 |
|
Erik Krogh Kristensen
|
86de10e6a1
|
simplify some implementations in UriLibraries.qll
|
2021-07-14 17:01:40 +02:00 |
|
Erik Krogh Kristensen
|
193ddfc771
|
add taint through the qs library
|
2021-07-14 16:56:51 +02:00 |
|
Aditya Sharad
|
e0a123cbd0
|
Merge pull request #6257 from github/rneatherway/summary-docs
Add docs for summary type queries
|
2021-07-14 07:54:18 -07:00 |
|
Taus
|
2bb44d49d9
|
Python: Perform more deduplication
This cut the evaluation time on `django` down from 1.2 seconds to ~0.8
seconds (but the impact will likely be greater on bigger projects).
|
2021-07-14 13:38:05 +00:00 |
|
Anders Schack-Mulligen
|
a0481bda91
|
Merge pull request #6282 from aschackmull/java/query-metadata2
Java: Add missing metadata.
|
2021-07-14 15:17:27 +02:00 |
|
Anders Schack-Mulligen
|
11fc23ba09
|
Merge pull request #6030 from smowton/smowton/admin/test-generator
Add test-generator script + add generated models for Spring summary steps
|
2021-07-14 14:44:07 +02:00 |
|
Anders Schack-Mulligen
|
9034b03c7b
|
Java: Add missing metadata.
|
2021-07-14 14:40:50 +02:00 |
|
Anders Schack-Mulligen
|
3a3398508c
|
Merge pull request #5895 from github/sauyon/java/spring
Add models for some Spring pseudo-collections
|
2021-07-14 14:40:24 +02:00 |
|
Sauyon Lee
|
d7bfc2eebf
|
Remove redundant model lines
|
2021-07-14 05:05:17 -07:00 |
|
Sauyon Lee
|
671243c15d
|
Add change note
|
2021-07-14 05:05:17 -07:00 |
|
Sauyon Lee
|
1f97ac88c8
|
Fix tests
|
2021-07-14 05:05:17 -07:00 |
|
Sauyon Lee
|
eaef1c146c
|
Add generated tests
|
2021-07-14 05:05:16 -07:00 |
|
Sauyon Lee
|
16931e5de8
|
Add necessary stubs for Spring
Co-Authored-By: smowton <smowton@github.com>
|
2021-07-14 04:57:56 -07:00 |
|
Sauyon Lee
|
fc7e062deb
|
Java: Add models for the Spring cache package
|
2021-07-14 04:57:56 -07:00 |
|
Sauyon Lee
|
d9fb09d132
|
Java: Add models for the Spring ui package.
|
2021-07-14 04:57:56 -07:00 |
|
Anders Schack-Mulligen
|
04244b3c45
|
Merge pull request #5974 from github/sauyon/java/spring-webmultipart
Model Spring `web.multipart`
|
2021-07-14 13:57:24 +02:00 |
|
Anders Schack-Mulligen
|
3c4cd15738
|
Merge pull request #5505 from joefarebrother/android-sql-convert
Java: Convert Android SQL-related flow steps to CSV format
|
2021-07-14 13:56:55 +02:00 |
|
Chris Smowton
|
e9390cb3eb
|
Remove superfluous conjunct
|
2021-07-14 12:42:28 +01:00 |
|
Taus
|
09993406f1
|
Python: Add explanatory QLDoc comment
|
2021-07-14 10:42:07 +00:00 |
|
Mathias Vorreiter Pedersen
|
0b21caa9ae
|
Merge pull request #6280 from MathiasVP/restrict-call-context-relation
C++: Potentially improve performance of call-context calculation
|
2021-07-14 12:15:26 +02:00 |
|
Mathias Vorreiter Pedersen
|
1480ac7c1d
|
C++: Potentially improve performance by restricting the size of the call-context relation.
|
2021-07-14 11:23:56 +02:00 |
|
Robin Neatherway
|
c9e642fb06
|
Merge branch 'main' into rneatherway/summary-docs
|
2021-07-14 10:13:32 +01:00 |
|
Chris Smowton
|
3ae99b93ca
|
Merge pull request #6215 from aschackmull/java/fix-csv-subtype-interpretation
Java: Fix CSV subtype interpretation
|
2021-07-14 09:57:21 +01:00 |
|
Anders Schack-Mulligen
|
0ccb213ec5
|
Dataflow: Sync.
|
2021-07-14 10:36:09 +02:00 |
|
Anders Schack-Mulligen
|
dbe1ca928b
|
Dataflow: Simplify call context checks.
|
2021-07-14 10:36:09 +02:00 |
|
Anders Schack-Mulligen
|
c95e78546c
|
Dataflow: Refactor
|
2021-07-14 10:36:09 +02:00 |
|
Erik Krogh Kristensen
|
73491d88da
|
use the new .toUnicode method in the Angular2 model
|
2021-07-14 10:19:48 +02:00 |
|