Michael Nebel
|
fe36230061
|
Merge pull request #14015 from michaelnebel/csharp/vscodesettings
C#: Update of VS Code settings.
|
2023-08-22 14:16:31 +02:00 |
|
Mathias Vorreiter Pedersen
|
1c3a0d1632
|
Update cpp/ql/src/Security/CWE/CWE-193/InvalidPointerDeref.qhelp
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
|
2023-08-22 13:03:07 +01:00 |
|
Mathias Vorreiter Pedersen
|
e88277bd3b
|
Update cpp/ql/src/Security/CWE/CWE-193/InvalidPointerDeref.qhelp
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
|
2023-08-22 13:02:37 +01:00 |
|
Mathias Vorreiter Pedersen
|
abe28cb106
|
Update cpp/ql/src/Security/CWE/CWE-193/InvalidPointerDeref.ql
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
|
2023-08-22 13:02:29 +01:00 |
|
Ian Lynagh
|
c67cc23e07
|
Kotlin: Write usesK2 information to the database
|
2023-08-22 12:37:01 +01:00 |
|
Tom Hvitved
|
31738a37ae
|
Merge pull request #14016 from hvitved/csharp/codeql-threads
C#: Respect `$CODEQL_THREADS` environment variable
|
2023-08-22 13:04:48 +02:00 |
|
Maiky
|
f301e46175
|
Remove isEmptyPassword predicate
|
2023-08-22 12:23:32 +02:00 |
|
yoff
|
00c0ebe9e4
|
Merge pull request #13738 from RasmusWL/path-steps
Python: Include all assignments in data flow paths
|
2023-08-22 11:58:11 +02:00 |
|
Michael Nebel
|
2b718fbc62
|
Merge pull request #13995 from michaelnebel/csharp/refactorimports
C#: Re-factor imports.
|
2023-08-22 11:52:02 +02:00 |
|
Tom Hvitved
|
6bb37ca465
|
C#: Respect $CODEQL_THREADS environment variable
|
2023-08-22 11:46:03 +02:00 |
|
Michael Nebel
|
b4c903fd15
|
C#: tasks.json no longer needed if C# Dev kit is installed.
|
2023-08-22 11:45:53 +02:00 |
|
Michael Nebel
|
8441b54bd8
|
C#: Set the extractor solution file as the default solution for the C# Dev Kit and add config for the Format usings plugin.
|
2023-08-22 11:35:47 +02:00 |
|
Michael Nebel
|
e9b1c933ed
|
C#: Recommend the C# Dev Kit and C# Format usings plugins.
|
2023-08-22 11:34:50 +02:00 |
|
Tom Hvitved
|
5192d7c137
|
Merge pull request #13997 from hvitved/ruby/type-tracking-splats
Ruby: Include more (hash) splat flow in type tracking
|
2023-08-22 11:33:39 +02:00 |
|
Tom Hvitved
|
3f54ecbcc2
|
Update ruby/ql/lib/codeql/ruby/typetracking/TypeTrackerSpecific.qll
Co-authored-by: Harry Maclean <hmac@github.com>
|
2023-08-22 11:18:12 +02:00 |
|
Alex Denisov
|
5cce37baa9
|
Swift: update test expectations
|
2023-08-22 11:11:28 +02:00 |
|
Alex Denisov
|
48607e3ad7
|
Swift: address code review comments
|
2023-08-22 10:01:16 +02:00 |
|
AlexDenisov
|
b98a966729
|
Apply suggestions from code review
Co-authored-by: Paolo Tranquilli <redsun82@github.com>
|
2023-08-22 09:57:25 +02:00 |
|
Anders Starcke Henriksen
|
3b8b33a94d
|
Released pack.
|
2023-08-22 09:45:52 +02:00 |
|
Anders Starcke Henriksen
|
3aeacf6df3
|
Update publish script to have right path.
|
2023-08-22 09:37:31 +02:00 |
|
Anders Schack-Mulligen
|
bdc5f9cdea
|
Merge pull request #14012 from knewbury01/knewbury01/add-sanitizer-command-query
Java: add sanitizer to command injection query
|
2023-08-22 08:40:49 +02:00 |
|
Michael Nebel
|
ce6fd8ac5f
|
Merge pull request #13432 from michaelnebel/updateissupported
Java/C#: Update telemetry queries to report callables with sink/source neutrals as being supported.
|
2023-08-22 08:39:38 +02:00 |
|
Sid Shankar
|
a9ea61f0b2
|
Merge pull request #14001 from github/sidshank/clarify-js-and-ts-requirements
Clarify system requirements for TypeScript extraction
|
2023-08-21 20:59:11 -04:00 |
|
Robert Marsh
|
a335ece5e5
|
Swift: change note for keypath optional flows
|
2023-08-21 20:11:37 +00:00 |
|
Robert Marsh
|
1634fa2e25
|
Swift: support for optional chaining in keypaths
|
2023-08-21 20:09:28 +00:00 |
|
Robert Marsh
|
81bf415b50
|
Swift: modify test so implicit read isn't needed at sink
|
2023-08-21 20:08:30 +00:00 |
|
Robert Marsh
|
246d5c530e
|
Swift: flow through keypath force components
|
2023-08-21 19:07:40 +00:00 |
|
Geoffrey White
|
f7776f812c
|
Swift: 'good enough' fix for UnsafeJsEval flow.
|
2023-08-21 18:30:30 +01:00 |
|
Henry Mercer
|
5a76b9f59e
|
Merge pull request #14010 from github/henrymercer/cs/add-alias
C#: Add "c#" alias to language pack
|
2023-08-21 18:26:54 +01:00 |
|
Geoffrey White
|
317757b7ae
|
Swift: Create proper models for JavaScriptCore.
|
2023-08-21 18:24:26 +01:00 |
|
Kristen Newbury
|
5e01e1d464
|
Java: add sanitizer to command injection query
|
2023-08-21 12:33:05 -04:00 |
|
Mathias Vorreiter Pedersen
|
e1ed49f3ac
|
Merge pull request #14011 from github/revert-13991-redsun82/swift-use-concepts
Revert "Swift: use C++20 constraints and concepts to simplify code"
|
2023-08-21 17:21:42 +01:00 |
|
Paolo Tranquilli
|
1daedd9fb6
|
Revert "Swift: use C++20 constraints and concepts to simplify code"
|
2023-08-21 17:40:15 +02:00 |
|
Henry Mercer
|
cbce0736c2
|
C#: Add "c#" alias to language pack
This will allow users to reference the C# extractor using
`--language c#` in future versions of the CLI.
|
2023-08-21 16:27:39 +01:00 |
|
Harry Maclean
|
414ae76ae1
|
Ruby: Add another splat flow test
|
2023-08-21 16:21:55 +01:00 |
|
Harry Maclean
|
c615f183c1
|
Ruby: Add test for spurious splat flow
We don't yet properly model splat flow when a positional argument
follows a splat argument.
|
2023-08-21 16:11:10 +01:00 |
|
Tamas Vajk
|
2575db356d
|
Improve code quality: fix review findings
|
2023-08-21 16:07:56 +02:00 |
|
Paolo Tranquilli
|
6d85d0d0f7
|
Merge pull request #13991 from github/redsun82/swift-use-concepts
Swift: use C++20 constraints and concepts to simplify code
|
2023-08-21 15:45:44 +02:00 |
|
Mathias Vorreiter Pedersen
|
ef9d342a99
|
C++: Accept more test changes.
|
2023-08-21 14:02:18 +01:00 |
|
Mathias Vorreiter Pedersen
|
c46f9e4572
|
C++: Don't consider additional loads when reusing dataflow operands.
|
2023-08-21 12:51:41 +01:00 |
|
Mathias Vorreiter Pedersen
|
50190efe1c
|
C++: Don't limit instruction and operand reuse to those cases where we have a result for 'isUseImpl'.
|
2023-08-21 12:51:00 +01:00 |
|
Tom Hvitved
|
12d1d04592
|
Merge pull request #13983 from hvitved/dataflow/reduced-dispatch-early-join
Data flow: Earlier call-context based dispatch filtering
|
2023-08-21 13:20:08 +02:00 |
|
Tom Hvitved
|
1b4520b058
|
Data flow: Update QL doc
|
2023-08-21 12:56:37 +02:00 |
|
Sid Shankar
|
671eb0f82f
|
Updates requirements for TypeScript only
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2023-08-21 06:51:30 -04:00 |
|
Jeroen Ketema
|
2d0f73d7c2
|
Merge pull request #13881 from jketema/shared-taint-tracking
Introduce shared taint tracking library
|
2023-08-21 12:45:49 +02:00 |
|
Geoffrey White
|
6ef6be7291
|
Swift: UnsafeJSEval regression.
|
2023-08-21 11:28:48 +01:00 |
|
Geoffrey White
|
997984c529
|
Swift: Minor test .expected changes.
|
2023-08-21 11:15:43 +01:00 |
|
Geoffrey White
|
a54747f850
|
Swift: Fix mysterious taint flow issue.
|
2023-08-21 11:06:04 +01:00 |
|
Rasmus Wriedt Larsen
|
c8c69aac9b
|
Merge pull request #13561 from amammad/amammad-python-WebAppsConstatntSecretKeys
Python: Flask & Django Constant Secret Key initialization
|
2023-08-21 11:39:19 +02:00 |
|
Mathias Vorreiter Pedersen
|
e776178be5
|
C++: Add some whitespace to make stuff appear in the diff.
|
2023-08-21 10:23:41 +01:00 |
|