Asger F
|
cac2e2e2e4
|
Merge pull request #10928 from asgerf/rb/assumed-global-const
Ruby: assume some global constants are defined
|
2022-10-24 14:06:34 +02:00 |
|
Asger F
|
0ffb0f6d4d
|
Ruby: constant lookup is unaffected by blocks
|
2022-10-24 13:07:21 +02:00 |
|
erik-krogh
|
07d90b34df
|
use instanceof in DirPathAccess
|
2022-10-24 12:05:26 +02:00 |
|
Erik Krogh Kristensen
|
669b0c35fe
|
fix qldoc
Co-authored-by: Nick Rolfe <nickrolfe@github.com>
|
2022-10-24 12:05:26 +02:00 |
|
erik-krogh
|
85cd7f9121
|
add model for Dir.glob and other Dir methods
|
2022-10-24 12:05:26 +02:00 |
|
Arthur Baars
|
b3855b089a
|
Ruby: some more tests
|
2022-10-22 14:15:29 +02:00 |
|
Arthur Baars
|
ccaa12998d
|
Ruby: desugar compound constant-assignments
|
2022-10-22 01:11:35 +02:00 |
|
Nick Rolfe
|
9fb436e22b
|
Ruby: add change note for localTaintStep fix
|
2022-10-21 16:33:29 +01:00 |
|
Nick Rolfe
|
269c27757d
|
Ruby: include value-preserving flow in localTaintStep
|
2022-10-21 16:17:11 +01:00 |
|
Nick Rolfe
|
5319216c18
|
Ruby: add test of TaintTracking::localFlowStep
|
2022-10-21 16:04:04 +01:00 |
|
Asger F
|
84ae17dcbb
|
Ruby: ensure Object is a transitive superclass
|
2022-10-21 15:18:59 +02:00 |
|
Arthur Baars
|
a56ed88db2
|
Merge pull request #10920 from github/post-release-prep/codeql-cli-2.11.2
Post-release preparation for codeql-cli-2.11.2
|
2022-10-21 11:58:12 +02:00 |
|
Tom Hvitved
|
4422327c00
|
Ruby: Call-context sensitivity for singleton method calls
|
2022-10-21 11:48:25 +02:00 |
|
Asger F
|
3fd2b9ad7b
|
Ruby: add a comment
This would have saved me some time
|
2022-10-21 11:44:12 +02:00 |
|
Asger F
|
ee7970afcb
|
Ruby: treat String as a builtin
|
2022-10-21 11:44:11 +02:00 |
|
Asger F
|
db58e3357b
|
Ruby: allow speculative container qname resolution
|
2022-10-21 11:44:11 +02:00 |
|
github-actions[bot]
|
be7693283b
|
Post-release preparation for codeql-cli-2.11.2
|
2022-10-21 08:07:17 +00:00 |
|
Tom Hvitved
|
6feff7e3ed
|
Ruby: Add more data-flow call sensitivity tests
|
2022-10-21 09:36:34 +02:00 |
|
Asger F
|
d26b0892cf
|
Ruby: also add an AST test
|
2022-10-21 09:23:21 +02:00 |
|
Asger F
|
038bdecad7
|
Ruby: add test with compound assignment to a constant
|
2022-10-21 09:20:03 +02:00 |
|
Tom Hvitved
|
db699ae314
|
Ruby: Refactor call graph logic for singleton methods
|
2022-10-21 07:27:41 +02:00 |
|
thiggy1342
|
4e5c1f210d
|
Update ruby/ql/lib/change-notes/2022-10-20-expand-faraday-model-for-ssrf-sink
Co-authored-by: Rahul Zhade <rzhade3@users.noreply.github.com>
|
2022-10-20 17:33:17 -04:00 |
|
thiggy1342
|
244a3329e0
|
Merge branch 'main' into expand-ruby-ssrf-sinks-faraday-connection-new
|
2022-10-20 16:37:57 -04:00 |
|
thiggy1342
|
4c3e3e442a
|
Add Faraday::Connection.new as sink for SSRF query
|
2022-10-20 20:32:08 +00:00 |
|
Asger F
|
8c2c28dd56
|
Ruby: add test showing missing superclass edge
|
2022-10-20 15:56:58 +02:00 |
|
Arthur Baars
|
a520de3986
|
Merge pull request #10902 from github/release-prep/2.11.2
Release preparation for version 2.11.2
|
2022-10-20 15:55:44 +02:00 |
|
Arthur Baars
|
45c9a0d0b1
|
Apply suggestions from code review
Co-authored-by: Jeroen Ketema <93738568+jketema@users.noreply.github.com>
|
2022-10-20 15:22:29 +02:00 |
|
github-actions[bot]
|
9a0848bbc4
|
Release preparation for version 2.11.2
|
2022-10-20 11:05:19 +00:00 |
|
Tom Hvitved
|
faaead682e
|
Ruby: Block for steps into self parameters in trackModuleAccess
|
2022-10-20 13:00:12 +02:00 |
|
Tom Hvitved
|
bda98261cc
|
Ruby: Add more call graph tests
|
2022-10-20 12:59:32 +02:00 |
|
erik-krogh
|
bb8bcd4643
|
fix typo
|
2022-10-20 10:48:02 +02:00 |
|
erik-krogh
|
c13e8e4f48
|
Merge branch 'main' into formatTaint
|
2022-10-20 10:46:16 +02:00 |
|
erik-krogh
|
7797211118
|
Merge branch 'main' into unsafeRbCmd
|
2022-10-20 10:34:17 +02:00 |
|
erik-krogh
|
24916f8538
|
rename runsImmediately to runsArbitraryCode
|
2022-10-20 10:10:11 +02:00 |
|
erik-krogh
|
3dd89bb7bf
|
remove duplicate alerts due to multiple states reaching the same sink
|
2022-10-19 13:19:18 +02:00 |
|
erik-krogh
|
226bd1f321
|
add flow-state support to sanitizers in code-execution, and use that to refactor the string-concatenation-sanitizer
|
2022-10-19 13:06:54 +02:00 |
|
erik-krogh
|
3e51f6fa8e
|
use flow-states to remove FPs related to an attacker only controlling a substring in code-injection
|
2022-10-19 13:00:44 +02:00 |
|
erik-krogh
|
2a72e89090
|
add a runsImmediately predicate to CodeExecution (name chosen by Copilot)
|
2022-10-19 12:30:47 +02:00 |
|
erik-krogh
|
d77b31672d
|
add failing test for safe-ish uses of Object.send
|
2022-10-19 11:27:08 +02:00 |
|
erik-krogh
|
cb33d5aeff
|
add test for .send(..) in code-injection
|
2022-10-19 11:25:30 +02:00 |
|
erik-krogh
|
e29bf8ced2
|
Merge branch 'main' into html_safe
|
2022-10-18 19:49:37 +02:00 |
|
Tom Hvitved
|
6208071575
|
Merge pull request #10874 from hvitved/ruby/fix-test-syntax-error
Ruby: Fix syntax error in a test
|
2022-10-18 19:28:17 +02:00 |
|
Tom Hvitved
|
61b9065135
|
Ruby: Fix syntax error in a test
|
2022-10-18 16:49:32 +02:00 |
|
Arthur Baars
|
14f150c1f3
|
Merge pull request #10872 from aibaars/set-output
CI: update actions/cache to v3
|
2022-10-18 15:09:29 +02:00 |
|
Arthur Baars
|
f56e155080
|
CI: update actions/cache to v3
|
2022-10-18 14:07:52 +02:00 |
|
erik-krogh
|
8a3e255e12
|
remove FPs in rb/stored-xss from spurious sources
|
2022-10-18 11:07:48 +02:00 |
|
erik-krogh
|
e47e20c5e7
|
remove use of HtmlSafeCall from tests
|
2022-10-18 10:43:24 +02:00 |
|
erik-krogh
|
5a98f66bef
|
simplify the modeling of html_safe. Any call to html_safe is now considered an XSS sink
|
2022-10-18 10:43:22 +02:00 |
|
Tom Hvitved
|
19bcd287cb
|
Merge pull request #10867 from hvitved/ruby/orm-tracking-redundant-additional-step
Ruby: Remove redundant additional flow step from `OrmTracking::Configuration`
|
2022-10-18 10:03:51 +02:00 |
|
Tom Hvitved
|
d362296f1c
|
Merge pull request #10864 from hvitved/ruby/get-a-barrier-node-join-fix
Ruby: Fix bad join-order in `BarrierGuard::getABarrierNode`
|
2022-10-18 10:03:02 +02:00 |
|