Ahmed Farid
|
fd558604cc
|
Update TimingAttack.qll
|
2022-07-21 18:48:07 +01:00 |
|
Ahmed Farid
|
6a782f47a9
|
Update Frameworks.qll
|
2022-07-20 13:08:21 +01:00 |
|
Ahmed Farid
|
6871790793
|
Rename TimingAttackAgainstSignature.ql to TimingAttackAgainstHash.ql
|
2022-07-20 13:07:14 +01:00 |
|
Ahmed Farid
|
7d0d39e019
|
Update PossibleTimingAttackAgainstHash.ql
|
2022-07-20 13:05:49 +01:00 |
|
Ahmed Farid
|
ee743e61e9
|
Update TimingAttack.qll
|
2022-07-20 13:03:55 +01:00 |
|
Ahmed Farid
|
238d3250c3
|
Update Concepts.qll
|
2022-07-20 13:00:30 +01:00 |
|
Ahmed Farid
|
e7742bd87c
|
Create CryptographicOperation.qll
Provides models for Python's Cryptography-related libraries
|
2022-07-20 12:58:13 +01:00 |
|
Ahmed Farid
|
4f082e28e5
|
Update and rename TimingAttackAgainstSignature.py to TimingAttackAgainstHash.py
|
2022-07-20 12:26:57 +01:00 |
|
Ahmed Farid
|
b3925ae988
|
Update PossibleTimingAttackAgainstSignature.qlref
|
2022-07-20 00:57:26 +01:00 |
|
Ahmed Farid
|
3d092f9569
|
Update TimingAttackAgainstSignature.ql
|
2022-07-20 00:56:52 +01:00 |
|
Ahmed Farid
|
27d81548a7
|
Update PossibleTimingAttackAgainstHash.ql
|
2022-07-20 00:55:22 +01:00 |
|
Ahmed Farid
|
bfce1898b9
|
Update and rename PossibleTimingAttackAgainstSignature.ql to PossibleTimingAttackAgainstHash.ql
|
2022-07-20 00:49:09 +01:00 |
|
Ahmed Farid
|
7406273346
|
Update TimingAttack.qhelp
|
2022-07-14 17:56:58 +01:00 |
|
Ahmed Farid
|
f4654136d6
|
Update TimingAttack.qhelp
|
2022-07-14 17:56:13 +01:00 |
|
Taus
|
ec363166ba
|
Python: Make UserInputMsgConfig public
|
2022-07-11 15:24:31 +02:00 |
|
Ahmed Farid
|
f5d0791b4f
|
Update TimingAttack.qll
|
2022-06-29 00:56:15 +01:00 |
|
Ahmed Farid
|
98909c2069
|
Update TimingAttackAgainstSensitiveInfo.ql
|
2022-06-29 00:55:21 +01:00 |
|
Ahmed Farid
|
41b4c06f2d
|
Update TimingAttackAgainstSignature.ql
|
2022-06-29 00:54:44 +01:00 |
|
Ahmed Farid
|
e20fefc3ad
|
Update TimingAttackAgainstHeader.ql
|
2022-06-29 00:54:03 +01:00 |
|
Ahmed Farid
|
5742046edf
|
Update PossibleTimingAttackAgainstSignature.ql
|
2022-06-29 00:51:51 +01:00 |
|
Ahmed Farid
|
acbb4042df
|
Update TimingAttack.qhelp
|
2022-06-29 00:51:12 +01:00 |
|
root
|
655b9d4262
|
Python: Timing attack
|
2022-06-27 12:18:45 -04:00 |
|
Rasmus Wriedt Larsen
|
3248f7b423
|
Merge pull request #9649 from RasmusWL/certificate-modeling
Python/JS/Ruby: Ignore common words (like certain) as sensitive data source
|
2022-06-23 12:04:58 +02:00 |
|
Rasmus Wriedt Larsen
|
876ba71d9b
|
Python/JS/Ruby: Add change-note
|
2022-06-22 11:14:05 +02:00 |
|
Rasmus Wriedt Larsen
|
4be375521f
|
Python: Handle _ in sensitive-data-sources
|
2022-06-22 11:05:14 +02:00 |
|
Rasmus Wriedt Larsen
|
4a844312f4
|
Python: _ in var name not handled by sensitive-data-sources
|
2022-06-22 11:05:14 +02:00 |
|
Rasmus Wriedt Larsen
|
5dc2bb717a
|
Python: ignore common words (certain/concert) as sensitive source
|
2022-06-22 11:05:05 +02:00 |
|
Anders Schack-Mulligen
|
df6d68b215
|
Merge pull request #9618 from aschackmull/dataflow/deprecate-barrierguard-class
Dataflow: Deprecate BarrierGuard class
|
2022-06-22 10:44:08 +02:00 |
|
Rasmus Wriedt Larsen
|
abdcfd55c3
|
Python: uncertainty is treated as a certificate :O
|
2022-06-22 10:16:28 +02:00 |
|
Anders Schack-Mulligen
|
f8f9b7d3b4
|
Apply suggestions from code review
|
2022-06-21 14:11:36 +02:00 |
|
Edoardo Pirovano
|
70dbd92e25
|
Bump minor version of all regularly released packs
|
2022-06-21 11:22:58 +01:00 |
|
Edoardo Pirovano
|
ad02b85efa
|
Merge branch main into rc/3.6
|
2022-06-21 11:15:25 +01:00 |
|
Anders Schack-Mulligen
|
a4796e1542
|
Add change notes.
|
2022-06-21 11:17:47 +02:00 |
|
Anders Schack-Mulligen
|
a6c0a9e480
|
Python: one more fix
|
2022-06-21 09:19:45 +02:00 |
|
Anders Schack-Mulligen
|
a7c268f804
|
Python: adjust test.
|
2022-06-20 15:46:38 +02:00 |
|
Anders Schack-Mulligen
|
f473a0a961
|
Python: Deprecate and replace BarrierGuard class.
|
2022-06-20 15:46:38 +02:00 |
|
Rasmus Wriedt Larsen
|
ae44a941f9
|
Merge pull request #9421 from RasmusWL/inline-brackets
Inline Expectation Tests: Allow `tag[foo bar]`
|
2022-06-20 10:01:19 +02:00 |
|
Taus
|
3a328f6a3f
|
Merge pull request #6570 from yoff/python/broaden-noqa-regex
Python: Broaden noqa regex to allow comments
|
2022-06-17 23:56:39 +02:00 |
|
Rasmus Wriedt Larsen
|
5fb41e4894
|
Inline Expectation Tests: Disallow tag[[[foo bar]
|
2022-06-17 17:36:04 +02:00 |
|
Anders Schack-Mulligen
|
6518a01ded
|
Dataflow: Sync.
|
2022-06-16 11:25:28 +02:00 |
|
Taus
|
9bf2eb55ca
|
Python: Allow whitespace before colon
As suggested by @DimitriPapadopolous.
Also fixes the test output to account for the `noqa` annotation (with
added comment) that we're now detecting.
|
2022-06-16 11:16:58 +02:00 |
|
Rasmus Lerchedahl Petersen
|
98301332bd
|
Python: Broaden noqa regex
|
2022-06-16 11:16:58 +02:00 |
|
github-actions[bot]
|
1ed70d51d7
|
Post-release preparation for codeql-cli-2.9.4
|
2022-06-15 13:25:20 +00:00 |
|
yoff
|
f14a90ff09
|
Merge pull request #9200 from tausbn/python-modernise-weak-file-permissions-query
Python: Modernise weak file permissions query
|
2022-06-15 14:37:17 +02:00 |
|
yoff
|
9dbb451f41
|
Merge pull request #9463 from RasmusWL/req-wo-cert-validation
Python: Rewrite `py/request-without-cert-validation`
|
2022-06-15 13:00:57 +02:00 |
|
github-actions[bot]
|
104ac05f49
|
Release preparation for version 2.9.4
|
2022-06-15 08:22:38 +00:00 |
|
Rasmus Wriedt Larsen
|
cfd640b1b2
|
Python: Apply suggestions from code review
Co-authored-by: yoff <lerchedahl@gmail.com>
|
2022-06-14 16:47:24 +02:00 |
|
Taus
|
5b9c668e10
|
Python: Restrict test to Python 3
|
2022-06-14 12:58:35 +00:00 |
|
yoff
|
699761889d
|
Merge pull request #7127 from jty-team/jty/python/emailInjection
Python: CWE-079 - Add Email injection query
|
2022-06-14 10:54:16 +02:00 |
|
Alex Ford
|
8d195e3188
|
Merge pull request #9157 from alexrford/crypto-op-block-mode
Ruby/Python: Add a `BlockMode` concept for `CryptographicOperations`
|
2022-06-13 21:32:36 +02:00 |
|