Edward Minnix III
|
39a7c7bb12
|
Merge pull request #11282 from egregius313/egregiu313/webview-addjavascriptinterface
Java: Query for detecting addJavascriptInterface method calls
|
2022-12-19 11:28:45 -05:00 |
|
Tony Torralba
|
624c9ff834
|
Update java/ql/src/Security/CWE/CWE-295/AndroidMissingCertificatePinning1.java
|
2022-12-19 17:26:41 +01:00 |
|
Arthur Baars
|
a8be5d7274
|
AlertSuppression: add change notes
|
2022-12-19 17:02:52 +01:00 |
|
Arthur Baars
|
0f313231bc
|
AlertSuppression: add more tests
|
2022-12-19 16:43:11 +01:00 |
|
Jeroen Ketema
|
0c710479ec
|
C++: Update experimental test changes
|
2022-12-19 16:35:24 +01:00 |
|
Tony Torralba
|
0c6ace350f
|
Update java/ql/src/Security/CWE/CWE-295/AndroidMissingCertificatePinning.ql
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
|
2022-12-19 16:24:39 +01:00 |
|
Calum Grant
|
0894059d33
|
Ruby: Remove reference to LGTM
|
2022-12-19 15:15:43 +00:00 |
|
Calum Grant
|
a1d229e445
|
Python: Remove references to LGTM
|
2022-12-19 15:15:32 +00:00 |
|
Calum Grant
|
4a37c01c5f
|
JavaScript: Remove references to LGTM
|
2022-12-19 15:15:17 +00:00 |
|
Arthur Baars
|
c9739b21cb
|
AlertSuppression: add support for //codeql comments
|
2022-12-19 16:10:28 +01:00 |
|
Arthur Baars
|
c176606be5
|
AlertSuppression: allow //lgtm comments to scope over the next line
|
2022-12-19 16:10:26 +01:00 |
|
Arthur Baars
|
016c7a8ca7
|
Merge pull request #11719 from aibaars/alert-suppression-shared
Shared AlertSuppression library
|
2022-12-19 16:04:44 +01:00 |
|
Henning Makholm
|
ca1c46331a
|
Merge pull request #11731 from github/hmakholm/pr/no-option
remove com.semmle.util.data.Option from from extractor code interface II
|
2022-12-19 15:36:51 +01:00 |
|
Erik Krogh Kristensen
|
f136651384
|
Merge pull request #11575 from erik-krogh/kernelLoad
Rb: add Kernel methods as sinks to path-injection
|
2022-12-19 15:09:21 +01:00 |
|
Jami Cogswell
|
a8ee633acd
|
Java: apply review suggestions
|
2022-12-19 09:09:01 -05:00 |
|
James Fletcher
|
55a04e7ff8
|
Merge pull request #11736 from github/jf205-patch-1
Update query-classification-and-display.md
|
2022-12-19 14:00:21 +00:00 |
|
Jami Cogswell
|
f37f0a09aa
|
Java: update change note
|
2022-12-19 08:41:56 -05:00 |
|
Jami Cogswell
|
42ddd66360
|
Java: add hasApiName predicate
|
2022-12-19 08:38:12 -05:00 |
|
erik-krogh
|
66be8cda06
|
remove more of the implementation into ConditionalBypassQuery.qll
|
2022-12-19 14:37:19 +01:00 |
|
Arthur Baars
|
8be882f815
|
Update javascript/ql/src/AlertSuppression.ql
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2022-12-19 14:35:16 +01:00 |
|
erik-krogh
|
d0af30b40a
|
cleanup the implementation of toString() for `SuperCall
|
2022-12-19 14:28:01 +01:00 |
|
James Fletcher
|
23047d8246
|
Delete query-classification-and-display.md
|
2022-12-19 13:24:52 +00:00 |
|
James Fletcher
|
af5de55d1f
|
Merge pull request #11737 from github/jf205-patch-2
Update supported-queries.md
|
2022-12-19 13:22:10 +00:00 |
|
Arthur Baars
|
682bf6d3a7
|
Apply suggestions from code review
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2022-12-19 14:16:05 +01:00 |
|
Chris Smowton
|
2ca56e0c1e
|
Java: handle printing an empty comment (/**/); add relevant tests
|
2022-12-19 14:12:09 +01:00 |
|
James Fletcher
|
75b63bbb0e
|
Update supported-queries.md
Removes mentions of LGTM.
|
2022-12-19 13:11:31 +00:00 |
|
James Fletcher
|
af60851233
|
Update query-classification-and-display.md
Removes the section about queries run on LGTM.com.
|
2022-12-19 12:52:32 +00:00 |
|
Jeroen Ketema
|
edd29f4b0e
|
C++: Add change note
|
2022-12-19 13:50:50 +01:00 |
|
yoff
|
5f0cde5be7
|
Merge branch 'main' into python/support-grouped-exceptions
|
2022-12-19 13:38:25 +01:00 |
|
yoff
|
d4eb2b964c
|
Merge pull request #11699 from erik-krogh/shareHost
Dynamic: Share more regexp code
|
2022-12-19 13:29:53 +01:00 |
|
Jeroen Ketema
|
ed33b905a6
|
C++: Simplify cpp/path-injection now argv sources are parameters
|
2022-12-19 12:54:16 +01:00 |
|
Jeroen Ketema
|
7549915773
|
C++: Accept test changes
|
2022-12-19 12:52:35 +01:00 |
|
Arthur Baars
|
06736e3e91
|
Add .gitattributes for Windows test files
|
2022-12-19 12:39:01 +01:00 |
|
Arthur Baars
|
f68e18cd9c
|
Python: move AlertSuppression.ql
|
2022-12-19 12:39:01 +01:00 |
|
Arthur Baars
|
acb5d6e163
|
Python: use shared AlertSuppression.qll
|
2022-12-19 12:26:12 +01:00 |
|
Arthur Baars
|
621a108846
|
Ruby: use shared AlertSuppression.qll
|
2022-12-19 12:26:06 +01:00 |
|
Arthur Baars
|
453045e276
|
C#: use shared AlertSuppression.qll
|
2022-12-19 12:25:50 +01:00 |
|
Arthur Baars
|
ad80822a52
|
C/C++: use shared AlertSuppression.qll
|
2022-12-19 12:25:46 +01:00 |
|
Arthur Baars
|
b0e8085765
|
Go: use shared AlertSuppression.qll
|
2022-12-19 12:25:21 +01:00 |
|
Arthur Baars
|
23f595bea1
|
JavaScript: use shared AlertSuppression.qll
|
2022-12-19 12:25:17 +01:00 |
|
Jeroen Ketema
|
a73bd050f7
|
C++: Define the argv flow source in terms the input parameter
|
2022-12-19 12:13:39 +01:00 |
|
Jeroen Ketema
|
2705aebbbc
|
C++: Restrict CWE-119 semmle tests to have a single main function
|
2022-12-19 12:13:37 +01:00 |
|
Tony Torralba
|
484a16ce1b
|
Update java/ql/src/Security/CWE/CWE-295/AndroidMissingCertificatePinning.ql
|
2022-12-19 12:10:32 +01:00 |
|
Arthur Baars
|
bc646d407e
|
Java: use shared AlertSuppression.qll
|
2022-12-19 12:07:28 +01:00 |
|
Arthur Baars
|
072a180093
|
Util: add AlertSuppression.qll
|
2022-12-19 12:06:36 +01:00 |
|
erik-krogh
|
442749bb7f
|
JS: add heuristic variants of queries that use RemoteFlowSource
|
2022-12-19 12:01:22 +01:00 |
|
Tony Torralba
|
a880fecc8b
|
Apply suggestions from code review
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
|
2022-12-19 11:56:36 +01:00 |
|
erik-krogh
|
2f84b21c7f
|
QL: add getQueryName to QueryDoc
|
2022-12-19 11:29:20 +01:00 |
|
erik-krogh
|
6c8b1cf4be
|
changes based on Python review
|
2022-12-19 11:20:31 +01:00 |
|
Jean Helie
|
31f7702a04
|
Merge pull request #11726 from github/jhelie/fix-endpoint-large-scale-script
ATM: fix script updating endpoint large scale test data
|
2022-12-19 10:55:30 +01:00 |
|