Anders Schack-Mulligen
|
f1ec2e3260
|
Merge pull request #8426 from atorralba/atorralba/missing-severities
Java: Add missing security-severity scores
|
2022-03-31 14:53:47 +02:00 |
|
Chris Smowton
|
767453520e
|
Merge pull request #8032 from JLLeitschuh/feat/JLL/check_os
Java: Add Guard Classes for checking OS & unify System Property Access
|
2022-03-18 11:20:36 +00:00 |
|
Chris Smowton
|
b11340c829
|
Change note tense and detail level
|
2022-03-16 10:34:25 +00:00 |
|
Arthur Baars
|
6a74e761c8
|
Merge pull request #8398 from github/post-release-prep/codeql-cli-2.8.3
Post-release preparation for codeql-cli-2.8.3
|
2022-03-14 21:05:09 +01:00 |
|
Tony Torralba
|
1f4f4207b5
|
Add missing security-severity scores
|
2022-03-14 09:50:14 +01:00 |
|
Joe Farebrother
|
b924de631f
|
Add change note, minor docs improvement
|
2022-03-11 17:58:52 +00:00 |
|
github-actions[bot]
|
6b194bc55f
|
Release preparation for version 2.8.3
|
2022-03-10 19:43:58 +00:00 |
|
Jonathan Leitschuh
|
b282c7f1b9
|
Apply suggestions from code review
Co-authored-by: Marcono1234 <Marcono1234@users.noreply.github.com>
Co-authored-by: Chris Smowton <smowton@github.com>
|
2022-03-07 11:31:32 -05:00 |
|
Jonathan Leitschuh
|
523ddb79f3
|
Cleanup after code review feedback
|
2022-03-04 15:35:01 -05:00 |
|
Jonathan Leitschuh
|
7ab193dde2
|
Add System.getProperties().getProperty support
|
2022-03-03 20:08:38 -05:00 |
|
Jonathan Leitschuh
|
39828fd596
|
Apply OS guard checks to TempDirLocalInformationDisclosure
|
2022-03-02 12:50:37 -05:00 |
|
github-actions[bot]
|
20fe22c8c8
|
Release preparation for version 2.8.2
|
2022-02-24 14:57:08 +00:00 |
|
Arthur Baars
|
ebb87c4b36
|
Merge pull request #7975 from github/post-release-prep/codeql-cli-2.8.1
Post-release preparation for codeql-cli-2.8.1
|
2022-02-15 20:17:35 +01:00 |
|
Tony Torralba
|
bfa14fa066
|
Merge pull request #7823 from JLLeitschuh/improve/JLL/combined_http_headers
Java: Add HTTP Request Splitting to Netty Query
|
2022-02-15 10:24:36 +01:00 |
|
Chris Smowton
|
0bf6c83ef2
|
Merge pull request #4388 from JLLeitschuh/feat/JLL/java/CWE-200_temp_directory_local_information_disclosure
Java: CWE-200: Temp directory local information disclosure vulnerability
|
2022-02-14 18:58:44 +00:00 |
|
Jonathan Leitschuh
|
2048aed0a9
|
Review feedback and improve temp dir vulnerable/safe code sugestion
|
2022-02-14 11:29:16 -05:00 |
|
github-actions[bot]
|
f25fc70b7c
|
Release preparation for version 2.8.1
|
2022-02-10 22:08:24 +00:00 |
|
Jonathan Leitschuh
|
c732cb7759
|
Add HTTP Request Splitting to Netty Query
|
2022-02-09 12:28:10 -05:00 |
|
Tom Hvitved
|
9440a45015
|
Merge branch 'main' into post-release-prep/codeql-cli-2.8.0
|
2022-02-09 09:40:33 +01:00 |
|
Chris Smowton
|
79654592d9
|
Apply suggestions from code review
|
2022-02-08 10:23:46 +00:00 |
|
Jonathan Leitschuh
|
1f47ea5164
|
Update to new change note format
|
2022-02-04 17:16:12 -05:00 |
|
Tony Torralba
|
4f13bf8941
|
Merge pull request #6492 from atorralba/atorralba/android-cleartext-storage-database
Java: Create new query Cleartext storage of sensitive information in Android databases
|
2022-02-02 16:23:05 +01:00 |
|
github-actions[bot]
|
634134f283
|
Release preparation for version 2.8.0
|
2022-01-27 10:40:20 +00:00 |
|
Edoardo Pirovano
|
1b539eb4dc
|
Merge branch rc/3.4 into main
|
2022-01-25 16:22:01 +00:00 |
|
Tony Torralba
|
b59fd4070f
|
Merge pull request #7136 from atorralba/atorralba/promote-insecure-trustmanager
Java: Promote Insecure TrustManager from experimental
|
2022-01-24 14:05:14 +01:00 |
|
Tony Torralba
|
f0604e2e84
|
Added query for Cleartext Storage in Android Database
|
2022-01-21 16:55:42 +01:00 |
|
Tony Torralba
|
3f6e035016
|
Docs improvements
|
2022-01-21 11:37:02 +01:00 |
|
Tony Torralba
|
8767d2db23
|
Don't capitalize the term content provider
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
|
2022-01-20 13:23:52 +01:00 |
|
Tony Torralba
|
ab560234e3
|
Update java/change-notes/2021-10-27-android-intent-uri-permission-manipulation-query.md
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
|
2022-01-20 13:23:51 +01:00 |
|
Tony Torralba
|
6152c8a989
|
Add change note
|
2022-01-20 13:23:48 +01:00 |
|
Tony Torralba
|
77c2b43560
|
Add change note and severity score
|
2022-01-20 10:24:43 +01:00 |
|
github-actions[bot]
|
4ce8ccc52b
|
Release preparation for version 2.7.6
|
2022-01-20 08:21:18 +00:00 |
|
Tony Torralba
|
000a544729
|
Decouple UnsafeCertTrust.qll to reuse the taint tracking configuration
|
2022-01-19 16:43:43 +01:00 |
|
Tony Torralba
|
5997b874de
|
Add change note
|
2022-01-19 16:42:53 +01:00 |
|
Chris Smowton
|
162b3822dd
|
Merge pull request #7613 from github/smowton/admin/tag-random-used-once
Remove security-severity tag to java/random-used-once
|
2022-01-19 14:43:08 +00:00 |
|
Chris Smowton
|
c63fcb2c69
|
Add change note
|
2022-01-19 14:13:45 +00:00 |
|
Tony Torralba
|
f103d45340
|
Merge branch 'main' into atorralba/android-implicit-pending-intents
|
2022-01-18 10:50:49 +01:00 |
|
Tony Torralba
|
e967b8a9be
|
Merge pull request #6576 from atorralba/atorralba/android-cleartext-storage-filesystem
Java: Create new query Cleartext storage of sensitive information in Android filesystem
|
2022-01-17 14:02:38 +01:00 |
|
Tony Torralba
|
227929508f
|
Merge pull request #6923 from atorralba/atorralba/android-fragment-injection
Java: CWE-470 - Queries to detect Fragment Injection in Android applications
|
2022-01-17 14:02:15 +01:00 |
|
Tony Torralba
|
c1ac09a063
|
Added query for Cleartext Storage in Android Filesystem
|
2022-01-17 11:11:00 +01:00 |
|
Andrew Eisenberg
|
fbb5d7196f
|
Merge branch 'main' into post-release-prep/codeql-cli-2.7.5
|
2022-01-14 08:23:43 -08:00 |
|
Tony Torralba
|
6f06be9419
|
Update change note
|
2022-01-14 10:33:19 +01:00 |
|
Tony Torralba
|
a0a914466c
|
Rewording
|
2022-01-14 10:32:33 +01:00 |
|
Tony Torralba
|
1e3e48132c
|
Rewording
|
2022-01-14 10:31:59 +01:00 |
|
Tony Torralba
|
d0077b8c12
|
Added query ImplicitPendingIntents
|
2022-01-14 10:31:53 +01:00 |
|
Tony Torralba
|
7b0d9ea525
|
Merge pull request #7054 from atorralba/atorralba/promote-log-injection
Java: Promote Log Injection from experimental
|
2022-01-11 17:26:18 +01:00 |
|
Tony Torralba
|
50caf7d8dc
|
Move change note to new location and remove import
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2022-01-11 12:24:44 +01:00 |
|
Tony Torralba
|
b9e32208ee
|
Move change note to new location
|
2022-01-11 12:23:16 +01:00 |
|
github-actions[bot]
|
1dfcf427aa
|
Release preparation for version 2.7.5
|
2022-01-04 14:44:56 +00:00 |
|
Tony Torralba
|
6dfe0ce7c5
|
Adapt chage note to new format
|
2021-12-15 16:57:20 +01:00 |
|