Michael B. Gale
|
ed79113c7f
|
Merge pull request #13180 from github/mbg/java/fix-java-version-too-old
Java: Hide GHA variables in `java-version-too-old` test
|
2023-05-16 15:49:38 +01:00 |
|
Tom Hvitved
|
3027ed2ca8
|
C#: Include arguments to ILogger extension method calls in LogMessageSink
|
2023-05-16 16:04:58 +02:00 |
|
Geoffrey White
|
35b35ec377
|
Swift: Mirror changes made in the docs.
|
2023-05-16 14:26:16 +01:00 |
|
Michael B. Gale
|
9660b47879
|
Hide GHA variables in java-version-too-old test
|
2023-05-16 14:20:17 +01:00 |
|
Alexandre Boulgakov
|
9e9be4fc5e
|
Merge pull request #13169 from github/sashabu/swift-tests
Swift: Use `...` to find and run all Bazel tests instead of having list them.
|
2023-05-16 14:20:03 +01:00 |
|
Paolo Tranquilli
|
8291b2229a
|
Swift: turn internal error into a TSP warning
|
2023-05-16 15:18:29 +02:00 |
|
Geoffrey White
|
94b4ebe38b
|
Update swift/ql/src/queries/Security/CWE-312/CleartextLogging.ql
Co-authored-by: Mathias Vorreiter Pedersen <mathiasvp@github.com>
|
2023-05-16 14:16:30 +01:00 |
|
Rasmus Lerchedahl Petersen
|
5d68473d12
|
python: elide nodes without location from basic
|
2023-05-16 14:38:51 +02:00 |
|
Rasmus Lerchedahl Petersen
|
5b4f98d6c4
|
python: Add summaries for container constructors
Also:
- turn on flow summaries for taint
- do not restrict node type
(as now we need summary nodes)
|
2023-05-16 14:38:51 +02:00 |
|
Jeroen Ketema
|
e8423f858f
|
Merge pull request #13149 from MathiasVP/barrier-out-on-phi-back-edges
C++: Block flow through back-edges in `cpp/overrun-write`
|
2023-05-16 14:22:55 +02:00 |
|
Mathias Vorreiter Pedersen
|
03ef18b286
|
Swift: Recommend a proper source of randomness in 'swift/hardcoded-key'.
|
2023-05-16 11:59:41 +01:00 |
|
Kasper Svendsen
|
843640c486
|
Merge pull request #13173 from kaspersv/kaspersv/enable-implicit-this-warnings-shared-packs
Enable implicit this warnings for shared packs
|
2023-05-16 10:50:28 +02:00 |
|
Rasmus Lerchedahl Petersen
|
145eaf3947
|
python: remove steps for container constructors
|
2023-05-16 10:35:10 +02:00 |
|
Tony Torralba
|
770099f210
|
Merge branch 'main' into atorralba/java/promote-xxe-experimental-sinks
|
2023-05-16 09:49:34 +02:00 |
|
Kasper Svendsen
|
bfb098c3d6
|
Enable implicit this warnings for shared packs
|
2023-05-16 09:22:29 +02:00 |
|
Tony Torralba
|
ac1df4de91
|
Merge pull request #13166 from atorralba/atorralba/java/xpath-xxe-sink
Java: Add `XPath.evaluate` as XXE sink
|
2023-05-16 09:14:56 +02:00 |
|
Erik Krogh Kristensen
|
57858afbd9
|
Merge pull request #13165 from erik-krogh/proto-assign-qhelp
JS: fixup in the qhelp for `js/prototype-polluting-assignment`
|
2023-05-16 08:52:52 +02:00 |
|
Owen Mansel-Chan
|
1a9bd9ccde
|
Merge pull request #13135 from owen-mc/go/fix-unit-test
Go: fix unit test
|
2023-05-16 07:50:50 +01:00 |
|
Alexandre Boulgakov
|
8db945a11e
|
Swift: Use ... to find and run all Bazel tests instead of having to list them.
|
2023-05-15 20:51:31 +01:00 |
|
Philip Ginsbach
|
167a5723b4
|
Merge pull request #13156 from github/ginsbach/SpecifyParameterisedSyntax
add parameter syntax for module declarations and module references
|
2023-05-15 17:07:20 +01:00 |
|
Tony Torralba
|
7d79d87d48
|
Add XPath.evaluate as XXE sink
|
2023-05-15 17:39:35 +02:00 |
|
erik-krogh
|
2ebce99eae
|
add another example of how to fix the prototype pollution issue
|
2023-05-15 17:24:02 +02:00 |
|
erik-krogh
|
7a338c408e
|
fix typo, the variable in the example is called items
|
2023-05-15 17:23:40 +02:00 |
|
Geoffrey White
|
4781881a6a
|
Swift: Improve mobile/phone number regexp.
|
2023-05-15 15:30:30 +01:00 |
|
Tom Hvitved
|
826b6219a0
|
Ruby: Include self parameters in type tracking flow-through logic
|
2023-05-15 16:02:33 +02:00 |
|
Tom Hvitved
|
3cdb27725a
|
Ruby: Add more call graph tests
|
2023-05-15 16:02:33 +02:00 |
|
Tom Hvitved
|
9dede31c0d
|
Merge pull request #13077 from hvitved/ruby/track-regexp-improvements
Ruby: Improvements to `RegExpTracking`
|
2023-05-15 16:02:00 +02:00 |
|
Geoffrey White
|
a0cba8cb6b
|
Swift: Address boolean value FPs.
|
2023-05-15 14:24:18 +01:00 |
|
Geoffrey White
|
27c8eb301e
|
Swift: Fix URL-related FPs.
|
2023-05-15 14:08:43 +01:00 |
|
Mathias Vorreiter Pedersen
|
650e9e1088
|
C++: Fix Code Scanning error.
|
2023-05-15 14:05:41 +01:00 |
|
Mathias Vorreiter Pedersen
|
f1c124a3da
|
C++: Share more code between 'ValidState' and 'StringSizeConfig'.
|
2023-05-15 14:01:17 +01:00 |
|
Geoffrey White
|
e59d7e0345
|
Swift: Remove assumption that 'username' is not sensitive (in the tests).
|
2023-05-15 13:58:44 +01:00 |
|
Geoffrey White
|
dba951111a
|
Swift: Add more sensitive data test cases.
|
2023-05-15 13:58:44 +01:00 |
|
Paolo Tranquilli
|
725a0a5eec
|
Merge pull request #13161 from github/redsun82/swift-markdown-diagnostics
Swift: support markdown TSP diagnostics
|
2023-05-15 14:47:59 +02:00 |
|
Mathias Vorreiter Pedersen
|
f31709fb29
|
C++: Make comment more clear.
|
2023-05-15 13:36:29 +01:00 |
|
Paolo Tranquilli
|
10d084fbbf
|
Swift: update comment
|
2023-05-15 13:48:24 +02:00 |
|
Paolo Tranquilli
|
cfcd26cf0d
|
Swift: support markdown TSP diagnostics
|
2023-05-15 13:48:24 +02:00 |
|
Paolo Tranquilli
|
d8c0054ea9
|
Merge pull request #13133 from github/redsun82/swift-diagnostics-locations
Swift: add location and visibility support to TSP diagnostics
|
2023-05-15 13:47:52 +02:00 |
|
Geoffrey White
|
2a4d7cb642
|
Swift: Make the result message consistent as well.
|
2023-05-15 11:53:58 +01:00 |
|
Mathias Vorreiter Pedersen
|
a7712b608a
|
C++: Add more comments.
|
2023-05-15 11:14:06 +01:00 |
|
Geoffrey White
|
3193b3b171
|
Swift: Make the CleartextLogging.ql query ID consistent with the other swift/cleartext-* queries.
|
2023-05-15 10:51:21 +01:00 |
|
Rasmus Wriedt Larsen
|
4be226ffe4
|
Merge pull request #13113 from yoff/python/test-container-steps
python: Add tests for container steps
|
2023-05-15 11:07:27 +02:00 |
|
Asger F
|
20e8ee8423
|
Merge pull request #12748 from JarLob/yi
JS: Add more sources, more unit tests, fixes to the GitHub Actions injection query
|
2023-05-15 11:03:00 +02:00 |
|
Tom Hvitved
|
cc6da7e38e
|
Merge pull request #13031 from hvitved/identity-consistency-check
C#: Remove local identity flow steps
|
2023-05-15 10:45:35 +02:00 |
|
Paolo Tranquilli
|
dbff3e4fa4
|
Swift: remove unneeded SwiftDiagnosticLogWrapper
|
2023-05-15 10:08:43 +02:00 |
|
Paolo Tranquilli
|
a2cb331ebe
|
Swift: remove hacky binlog interception
|
2023-05-15 10:02:24 +02:00 |
|
Paolo Tranquilli
|
9a555aea5f
|
Merge branch 'main' into redsun82/swift-diagnostics-locations
|
2023-05-15 10:01:45 +02:00 |
|
Tom Hvitved
|
027cb2d335
|
C#: Reenable consistency check
|
2023-05-15 09:36:37 +02:00 |
|
Tom Hvitved
|
3c173df69e
|
C#: Update expected test output
|
2023-05-15 09:35:20 +02:00 |
|
Tom Hvitved
|
165dc0b9bf
|
C#: Filter away phi (read) input steps from a node into itself
|
2023-05-15 09:35:04 +02:00 |
|