Tony Torralba
|
2b3cab355d
|
Merge pull request #13859 from github/workflow/coverage/update
Update CSV framework coverage reports
|
2023-08-01 09:18:20 +02:00 |
|
Jeroen Ketema
|
ef8d95f87d
|
C++: Add IR test that shows dataflow regression after frontend update
|
2023-08-01 09:01:39 +02:00 |
|
Owen Mansel-Chan
|
5a5e921ee7
|
Merge pull request #13846 from owen-mc/go/better-baselines
Go: Add language-specific baseline configuration
|
2023-08-01 07:14:43 +01:00 |
|
Owen Mansel-Chan
|
a8c64443e8
|
Merge pull request #13645 from porcupineyhairs/goTiming
Go : Improvements to Timing Attacks query
|
2023-08-01 07:10:42 +01:00 |
|
github-actions[bot]
|
b547ae7c2f
|
Add changed framework coverage reports
|
2023-08-01 00:18:36 +00:00 |
|
Jeongsoo Lee
|
1d5eb4a960
|
Update javascript/ql/lib/change-notes/2023-07-28-mad-log-injection.md
Co-authored-by: Asger F <asgerf@github.com>
|
2023-07-31 15:38:35 -07:00 |
|
Cornelius Riemenschneider
|
caf2180bad
|
Update .bazelversion
|
2023-08-01 00:15:53 +02:00 |
|
Paul Hodgkinson
|
3bc7cf6ac7
|
Merge branch 'main' into java/experimental/command-injection
|
2023-07-31 19:14:55 +01:00 |
|
Jeongsoo Lee
|
9ab2a28de0
|
Merge branch 'main' into log-injection-mad
|
2023-07-31 09:55:35 -07:00 |
|
Felicity Chapman
|
df1e8e263b
|
Merge pull request #13854 from github/11185-add-note
CodeQL library update to use modular API interface - Add note and include in articles
|
2023-07-31 17:22:17 +01:00 |
|
Owen Mansel-Chan
|
d98079d72c
|
Apply suggestions from code review
Co-authored-by: Henry Mercer <henry.mercer@me.com>
|
2023-07-31 16:49:11 +01:00 |
|
Owen Mansel-Chan
|
216911dad9
|
Merge branch 'main' into goTiming
|
2023-07-31 16:15:10 +01:00 |
|
Owen Mansel-Chan
|
3d495bdd43
|
Add new files to CODEQL_TOOLS in Makefile
|
2023-07-31 16:12:52 +01:00 |
|
Owen Mansel-Chan
|
47a536c85d
|
Always output valid JSON containing paths-ignore
|
2023-07-31 16:09:47 +01:00 |
|
Alex Ford
|
af854749d7
|
Ruby: update Ldapinjection test output
|
2023-07-31 16:08:15 +01:00 |
|
Alex Ford
|
f437a6f729
|
Merge branch 'main' into maikypedia/ldap-injection
|
2023-07-31 16:00:41 +01:00 |
|
Alex Ford
|
558238a9be
|
Ruby: update TaintStep test output
|
2023-07-31 16:00:27 +01:00 |
|
Felicity Chapman
|
46f80dc5ca
|
Put back a missing colon to fix the link
|
2023-07-31 15:56:24 +01:00 |
|
Alex Ford
|
f272b0786a
|
Ruby: fix qldoc typo
|
2023-07-31 14:58:05 +01:00 |
|
Alex Ford
|
7f82aba7d4
|
qlformat
|
2023-07-31 14:57:14 +01:00 |
|
Alex Ford
|
2240e4bffb
|
Ruby: fix changenote date format
|
2023-07-31 14:56:53 +01:00 |
|
Felicity Chapman
|
9a334d3300
|
Add shortened link to changelog
|
2023-07-31 14:13:52 +01:00 |
|
Anders Schack-Mulligen
|
e87b8ba3d7
|
Java: Make the barrier in java/potentially-weak-cryptographic-algorithm less restrictive.
|
2023-07-31 14:28:53 +02:00 |
|
Asger F
|
a148c7cc87
|
JS: Mention log-injection sink kind in docs
|
2023-07-31 14:04:16 +02:00 |
|
Geoffrey White
|
1c64fb16f1
|
Merge pull request #13756 from geoffw0/sources2
Swift: CustomUrlSchemes test enhancements and minor model improvement
|
2023-07-31 12:53:03 +01:00 |
|
Asger F
|
da3eb28767
|
Apply suggestions from code review
Co-authored-by: Jorge <46056498+jorgectf@users.noreply.github.com>
|
2023-07-31 13:51:59 +02:00 |
|
Felicity Chapman
|
a0c0da78e9
|
Merge branch 'main' into 11185-add-note
|
2023-07-31 11:54:00 +01:00 |
|
Geoffrey White
|
c4b782407b
|
Merge pull request #13853 from geoffw0/commandinject
Swift: Autoformat experimental query.
|
2023-07-31 11:30:20 +01:00 |
|
Felicity Chapman
|
4d05b742d6
|
Merge branch 'main' into 11185-add-note
|
2023-07-31 10:58:03 +01:00 |
|
Felicity Chapman
|
32da3c3730
|
Add main note and include in articles
|
2023-07-31 10:50:47 +01:00 |
|
Geoffrey White
|
f921076fca
|
Swift: Autoformat.
|
2023-07-31 10:25:25 +01:00 |
|
Tony Torralba
|
5488abc512
|
Merge pull request #13850 from atorralba/atorralba/java/unimportant-generated-models
Java: Remove superfluous generated models
|
2023-07-31 11:25:03 +02:00 |
|
Tony Torralba
|
41f1315da9
|
Merge pull request #13772 from atorralba/atorralba/java/inputstream-wrapper-read-step
Java: Add taint steps for InputStream wrappers
|
2023-07-31 11:12:43 +02:00 |
|
Geoffrey White
|
e534afe634
|
Merge pull request #13726 from maikypedia/maikypedia/swift-command-injection
Swift: Add Command Injection query (CWE-078)
|
2023-07-31 10:06:22 +01:00 |
|
Geoffrey White
|
12f2539d1d
|
Swift: Use flowTo.
|
2023-07-31 10:03:25 +01:00 |
|
Mathias Vorreiter Pedersen
|
2562f8a297
|
Merge pull request #13844 from jketema/forgotten-paren
C++: Add forgotten parentheses in ternary IR test
|
2023-07-31 10:03:06 +02:00 |
|
Tony Torralba
|
3bd4d34a47
|
Java: Remove superfluous generated models
|
2023-07-31 09:48:03 +02:00 |
|
Porcupiney Hairs
|
74e5c15eaa
|
Go : Improvements to Timing Attacks query
|
2023-07-31 06:30:47 +05:30 |
|
Owen Mansel-Chan
|
b5518047fa
|
Go: Add language-specific baseline configuration
|
2023-07-30 21:52:33 +01:00 |
|
Mathias Vorreiter Pedersen
|
4656130dab
|
Merge pull request #13843 from MathiasVP/revert-13792
|
2023-07-30 01:18:00 +02:00 |
|
Jeroen Ketema
|
0bc75ea9b7
|
C++: Add forgotten parentheses in ternary IR test
Without the parentheses, the expressions are parsed as `a ? x : (y = val)`.
|
2023-07-29 18:44:28 +02:00 |
|
Owen Mansel-Chan
|
93e5b2260e
|
Merge pull request #13834 from owen-mc/go/fix-compiler-error-messages-for-1.20.6
Backport: Compiler error messages changed in Go 1.20.6
|
2023-07-29 13:45:19 +01:00 |
|
Mathias Vorreiter Pedersen
|
fd1949092c
|
C++: Accept test changes.
|
2023-07-29 11:29:06 +02:00 |
|
Mathias Vorreiter Pedersen
|
ce9a14b692
|
Revert "Merge pull request #13792 from MathiasVP/swap-argument-order-in-invalid-ptr-deref"
This reverts commit 1fa6511482, reversing
changes made to 4676ca5a4a.
|
2023-07-29 11:26:41 +02:00 |
|
Jeongsoo Lee
|
4529d8b75a
|
Add support for log injection in MaD
|
2023-07-28 22:37:56 +00:00 |
|
Sarita Iyer
|
f6b6a988ca
|
Update supported-frameworks.rst
|
2023-07-28 17:21:55 -04:00 |
|
Robert Marsh
|
22ae430e65
|
Swift: accept more test changes from hiding InOutExpr
|
2023-07-28 20:43:25 +00:00 |
|
Robert Marsh
|
bb4fe2002f
|
Merge branch 'main' into rdmarsh2/swift/array-content-flow
|
2023-07-28 20:41:23 +00:00 |
|
Alexandre Boulgakov
|
3e7a7fe54e
|
Swift: Mangle ArchetypeTypes with different constraints in different extensions.
|
2023-07-28 21:39:52 +01:00 |
|
Ian Lynagh
|
01a512b677
|
Kotlin: Pass on a parentId
|
2023-07-28 17:46:05 +01:00 |
|