Dave Bartolomeo
|
d069d91bf5
|
Merge pull request #6601 from dbartol/dbartol/side-effect-reorder/work
Fix order of IR call side effects
|
2022-01-26 17:02:02 -05:00 |
|
Mathias Vorreiter Pedersen
|
647d4d028e
|
Merge pull request #7758 from jketema/unnamed-variable-fix
C++: Do not report "Declaration hides variable" for unnamed variables
|
2022-01-26 15:36:04 +00:00 |
|
Jeroen Ketema
|
ee78cc731d
|
Add change note
|
2022-01-26 15:59:17 +01:00 |
|
Jeroen Ketema
|
9194af9b15
|
Do not report "Declaration hides variable" for unnamed variables
|
2022-01-26 15:10:37 +01:00 |
|
Jeroen Ketema
|
10a94cfa45
|
Add test for structured binding declaration hiding variable
|
2022-01-26 15:08:50 +01:00 |
|
Jeroen Ketema
|
b380ba0d8f
|
Add semmle-extractor-options: -std=c++17 to test
|
2022-01-26 15:05:21 +01:00 |
|
Dave Bartolomeo
|
4c42013836
|
Update test expectations
|
2022-01-25 15:22:13 -05:00 |
|
Edoardo Pirovano
|
662675ebf0
|
Merge pull request #7739 from github/edoardo/3.4-mergeback
Merge `rc/3.4` into `main`
|
2022-01-25 17:44:13 +00:00 |
|
Edoardo Pirovano
|
1b539eb4dc
|
Merge branch rc/3.4 into main
|
2022-01-25 16:22:01 +00:00 |
|
Geoffrey White
|
63ff17b3c1
|
Merge pull request #7737 from geoffw0/clrtxt5
C++: Upgrade cpp/cleartext-storage-file
|
2022-01-25 15:09:13 +00:00 |
|
Mathias Vorreiter Pedersen
|
72241886bf
|
C++: Add security-severity to 'cpp/return-stack-allocated-memory'.
|
2022-01-25 08:49:00 +00:00 |
|
Dave Bartolomeo
|
9183a4d7e7
|
Merge remote-tracking branch 'upstream/main' into dbartol/side-effect-reorder/work
|
2022-01-24 15:56:38 -05:00 |
|
Robert Marsh
|
6d3381cb89
|
Merge pull request #7718 from MathiasVP/move-return-stack-allocated-memory-into-code-scanning
C++: Add `security` tag to `cpp/return-stack-allocated-memory`
|
2022-01-24 14:52:23 -05:00 |
|
Geoffrey White
|
e42d3e540a
|
C++: Change note.
|
2022-01-24 18:32:17 +00:00 |
|
Geoffrey White
|
764f27f08e
|
C++: Upgrade to path-problem.
|
2022-01-24 18:32:05 +00:00 |
|
Geoffrey White
|
bbaac556e2
|
C++: Reveal the FP to be an issue with dataflow / model of strcpy.
|
2022-01-24 17:53:37 +00:00 |
|
Geoffrey White
|
11929378c7
|
C++: Upgrade cpp/cleartext-storage-file to full taint flow.
|
2022-01-24 17:48:45 +00:00 |
|
Mathias Vorreiter Pedersen
|
7db66055e5
|
C++: Add change note.
|
2022-01-24 11:57:25 +00:00 |
|
Mathias Vorreiter Pedersen
|
08379df613
|
C++: Add 'security' tag to 'cpp/return-stack-allocated-memory'.
|
2022-01-24 11:43:38 +00:00 |
|
Geoffrey White
|
4c99d39acf
|
Merge pull request #7701 from MathiasVP/remove-intentional-get-stack-pointer
C++: Remove FPs from `cpp/return-stack-allocated-memory`
|
2022-01-24 11:39:10 +00:00 |
|
Geoffrey White
|
683f909f7a
|
Merge pull request #7704 from geoffw0/clrtxt4
C++: Another improvement to cpp/cleartext-transmission
|
2022-01-24 10:11:11 +00:00 |
|
Geoffrey White
|
0b98397e9b
|
C++: Catch another encryption clue.
|
2022-01-21 16:16:16 +00:00 |
|
Geoffrey White
|
97447d0b3a
|
C++: Expand tests.
|
2022-01-21 16:16:15 +00:00 |
|
Mathias Vorreiter Pedersen
|
48064c1c8f
|
C++: Fix false positive.
|
2022-01-21 15:16:02 +00:00 |
|
Mathias Vorreiter Pedersen
|
7c8c2090f7
|
C++: Add real-world false positive from the 'cpp/return-stack-allocated-memory' query.
|
2022-01-21 15:14:18 +00:00 |
|
Mathias Vorreiter Pedersen
|
117795c409
|
Merge pull request #7682 from MathiasVP/rewrite-return-stack-allocated-memory-to-use-ir
C++: Use the IR for `cpp/return-stack-allocated-memory`.
|
2022-01-21 14:57:30 +00:00 |
|
Erik Krogh Kristensen
|
a235f8f023
|
remove redundant inline type casts
|
2022-01-21 11:46:33 +01:00 |
|
Erik Krogh Kristensen
|
f500bccbe4
|
add explicit this to member call
|
2022-01-21 11:46:33 +01:00 |
|
Mathias Vorreiter Pedersen
|
bd1720f797
|
C++: Add change note.
|
2022-01-20 18:27:09 +00:00 |
|
Mathias Vorreiter Pedersen
|
e689f6bad2
|
C++: Use the IR for 'cpp/return-stack-allocated-memory'.
|
2022-01-20 18:22:49 +00:00 |
|
Erik Krogh Kristensen
|
a77b2b0209
|
Merge pull request #7668 from erik-krogh/simplify-casts
simplify expressions that could be type-casts
|
2022-01-20 15:20:18 +01:00 |
|
Geoffrey White
|
b230681bc8
|
Merge pull request #7650 from geoffw0/clrtxt3
C++: Improve cpp/cleartext-transmission
|
2022-01-20 13:21:54 +00:00 |
|
github-actions[bot]
|
ab218421da
|
Post-release preparation for codeql-cli-2.7.6
|
2022-01-20 12:59:20 +00:00 |
|
Geoffrey White
|
8bdbaf4b57
|
C++: Autoformat.
|
2022-01-20 09:52:24 +00:00 |
|
Erik Krogh Kristensen
|
4e8e3a7420
|
simplify expressions that could be type-casts
|
2022-01-20 10:41:35 +01:00 |
|
github-actions[bot]
|
4ce8ccc52b
|
Release preparation for version 2.7.6
|
2022-01-20 08:21:18 +00:00 |
|
Mathias Vorreiter Pedersen
|
dfbde23821
|
Merge pull request #7627 from geoffw0/nullterm5
C++: Fix branch related FPs in cpp/improper-null-termination.
|
2022-01-19 13:30:05 +00:00 |
|
Geoffrey White
|
0230494799
|
C++: Expand QLDoc comment.
|
2022-01-19 13:07:55 +00:00 |
|
Geoffrey White
|
acfd593eb4
|
C++: Change note.
|
2022-01-19 13:00:36 +00:00 |
|
Geoffrey White
|
330b4c3704
|
C++: Generalize hasSocketInput a little to include fgets and friends.
|
2022-01-19 13:00:35 +00:00 |
|
Geoffrey White
|
9c2d961ae5
|
C++: Fix another expression of stdin / stdout we see in practice.
|
2022-01-19 13:00:34 +00:00 |
|
Geoffrey White
|
d77ba020f9
|
C++: Support more routines as proof-of-encryption in cpp/cleartext-transmission.
|
2022-01-19 12:40:32 +00:00 |
|
Geoffrey White
|
974a8b1a9a
|
C++: Add a test case.
|
2022-01-19 12:33:21 +00:00 |
|
Mathias Vorreiter Pedersen
|
bdfde88e99
|
Merge pull request #7630 from JarLob/patch-2
C++: Reduce FPs in IncorrectPrivilegeAssignment.ql
|
2022-01-19 09:49:43 +00:00 |
|
Jaroslav Lobačevski
|
a1b0315d90
|
Update cpp/ql/src/experimental/Security/CWE/CWE-266/IncorrectPrivilegeAssignment.ql
|
2022-01-19 00:52:10 +01:00 |
|
Jaroslav Lobačevski
|
3fa2516898
|
Update cpp/ql/src/experimental/Security/CWE/CWE-266/IncorrectPrivilegeAssignment.ql
|
2022-01-18 21:47:55 +01:00 |
|
Jaroslav Lobačevski
|
d1c89562b8
|
Apply suggestions from code review
|
2022-01-18 21:45:13 +01:00 |
|
Geoffrey White
|
982fb8f73a
|
C++: Add change note.
|
2022-01-18 16:38:44 +00:00 |
|
Robert Marsh
|
024bd27485
|
Merge pull request #7578 from MathiasVP/store-dest-should-not-be-use
C++: Store destinations should not be uses for dataflow SSA
|
2022-01-18 11:36:15 -05:00 |
|
Jaroslav Lobačevski
|
92f5a5f893
|
Reduce FPs in IncorrectPrivilegeAssignment.ql
Implements suggestions from https://github.com/github/codeql/pull/6949#issuecomment-976482965
|
2022-01-18 13:43:17 +01:00 |
|