Michael Nebel
|
dab4a61159
|
C#: Update flowsummaries expected test output.
|
2023-04-13 09:21:05 +02:00 |
|
Michael Nebel
|
6593991c13
|
Java/C#: Update generated models to have provenance df-generated.
|
2023-04-13 09:21:05 +02:00 |
|
Michael Nebel
|
03482e5e59
|
Java/C#: Update the internal documentation.
|
2023-04-13 09:21:05 +02:00 |
|
Michael Nebel
|
917cf7bfee
|
Go: Update provenance validation.
|
2023-04-13 09:21:05 +02:00 |
|
Michael Nebel
|
37abdc7a51
|
C#: Adjust the implementation to use the new predicates and Provenance.
|
2023-04-13 09:21:05 +02:00 |
|
Michael Nebel
|
1d82b09ec1
|
Sync files.
|
2023-04-13 09:21:05 +02:00 |
|
Michael Nebel
|
54e55e2262
|
Java: Introduce more provenance values.
|
2023-04-13 09:21:04 +02:00 |
|
Michael Nebel
|
efc0650b86
|
Java: Set the provenance default to manual.
|
2023-04-13 09:21:04 +02:00 |
|
Ed Minnix
|
2edad6ec71
|
Remove unused import
|
2023-04-12 20:42:26 -04:00 |
|
Ed Minnix
|
c756bdbc30
|
Fix naming in SensitiveCookieNotHttpOnly
|
2023-04-12 20:39:18 -04:00 |
|
Ed Minnix
|
c49bf01dc8
|
Refactor PermissiveDotRegex.ql
|
2023-04-12 20:37:36 -04:00 |
|
Ed Minnix
|
5164c2480f
|
Refactor SensitiveCookieNotHttpOnly
|
2023-04-12 20:37:36 -04:00 |
|
Ed Minnix
|
8f7d8cbcea
|
Refactor timing attack queries
|
2023-04-12 20:37:36 -04:00 |
|
Ed Minnix
|
597949dbfe
|
Refactor PermissiveDotRegexQuery
|
2023-04-12 20:37:36 -04:00 |
|
Ed Minnix
|
157b7ceaff
|
Refactor TimingAttackAgainstHeader
|
2023-04-12 20:37:36 -04:00 |
|
Ed Minnix
|
a186b771ba
|
Refactor JxBrowserWithoutCertValidation
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
ccdd9bce33
|
Refactor Revocation checking
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
380888e446
|
Refactor ClientSuppliedIpUsedInSecurityCheck
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
3c85ca9740
|
Refactor ThreadResourceAbuse
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
da5a719ffc
|
Refactor UnsafeUsageOfClientSideEncryptionVersion
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
e880a5f187
|
Refactor UnsafeTlsVersion
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
e3f6bc043d
|
Refactor InsecureWebResourceResponse
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
074745315c
|
Refactor SensitiveAndroidFileLeak
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
685a2043a8
|
Refactor UnsafeReflection
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
13e1cc50c8
|
Add SpringUrlRedirect
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
30cfbb83b3
|
Add UncaughtServletException
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
5594e7f6d2
|
Add SensitiveGetQuery
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
478309c90b
|
Add UnsafeDeserializationRmi
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
e2cfea19b5
|
Add UnsafeUrlForward
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
d48adbd175
|
Refactor JsonpInjection
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
8cb5e78832
|
Refactor XXE files
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
4c80ff03de
|
Refactor UnvalidatedCors
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
d254d91f57
|
Refactor Injection queries
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
7002ed5303
|
Refactor InsecureRmiJmxEnvironmentConfiguration
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
6e4e1e52c0
|
Refactor NFEAndroidDoS
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
94768f425f
|
Refactor HashWithoutSalt
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
cb7391177d
|
Refactor MyBatis queries
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
d528c8461f
|
Refactor XQueryInjection.ql
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
e7cbd493d7
|
Refactor FilePathInjection
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
47c5db03ab
|
Refactor OpenStream.ql
|
2023-04-12 20:37:34 -04:00 |
|
Ed Minnix
|
5bd9aae072
|
Refactor Log4jJndiInjection.ql
|
2023-04-12 20:37:34 -04:00 |
|
Asger F
|
2f82f4338a
|
QL: Dont ask me to inline cached predicates
|
2023-04-12 20:33:21 +02:00 |
|
Mathias Vorreiter Pedersen
|
184cb74cd0
|
Swift: Accept test changes.
|
2023-04-12 17:38:34 +01:00 |
|
Mathias Vorreiter Pedersen
|
f46ea325e8
|
Swift: Add dataflow through key-path expressios by modeling them as lambdas that perform a sequence of read steps.
|
2023-04-12 17:38:34 +01:00 |
|
Mathias Vorreiter Pedersen
|
21b03927c5
|
Swift: Add failing tests.
|
2023-04-12 17:38:29 +01:00 |
|
Chris Smowton
|
d049b112a9
|
Merge pull request #12750 from smowton/smowton/admin/add-dataflow-viableParamArgSpecific-hook
Go: mass-convert taint-flow models to models-as-data format (with `viableParamArgSpecific` hook)
|
2023-04-12 17:11:18 +01:00 |
|
Mathias Vorreiter Pedersen
|
ba4e3ae949
|
Update cpp/ql/src/Critical/FlowAfterFree.qll
Co-authored-by: Geoffrey White <40627776+geoffw0@users.noreply.github.com>
|
2023-04-12 16:50:57 +01:00 |
|
Mathew Payne
|
824ff8ad88
|
Add function signature to model
|
2023-04-12 14:54:06 +00:00 |
|
Mathew Payne
|
ffec22a5d2
|
Add change log notes
|
2023-04-12 14:48:28 +00:00 |
|
Mathew Payne
|
d0529bba2b
|
Add missing models for Java IO
- java.io.OutputStream
- java.nio.file.Files
|
2023-04-12 14:43:11 +00:00 |
|