Kevin Stubbings
|
52a0fdabcf
|
formatting
|
2023-10-27 00:03:30 -07:00 |
|
Tom Hvitved
|
08d6379563
|
C#: Regenerate stubs for (Asp)NetCore.App
|
2023-10-27 08:34:55 +02:00 |
|
Tom Hvitved
|
abc16abf6f
|
C#: Include AttributeUsages in stub generator
|
2023-10-27 08:34:20 +02:00 |
|
Kevin Stubbings
|
135923c9c1
|
Change XNetHtmltest
|
2023-10-26 20:48:38 -07:00 |
|
Mathias Vorreiter Pedersen
|
63525a9d9e
|
Swift: Delete one TODO (it has been converted to an internal issue) and fix another.
|
2023-10-26 21:48:41 +01:00 |
|
Kevin Stubbings
|
e6e87a44a3
|
Add change note
|
2023-10-26 12:36:35 -07:00 |
|
Dave Bartolomeo
|
d2afb20f3f
|
Merge remote-tracking branch 'origin/main' into dbartol/threat-models-2
|
2023-10-26 14:05:40 -04:00 |
|
Erik Krogh Kristensen
|
a5bfeb68a8
|
Merge pull request #14604 from erik-krogh/fix-thistype
JS: fix `TypeExprKinds` crashing on a `ThisExpression`
|
2023-10-26 20:05:26 +02:00 |
|
Dave Bartolomeo
|
9800458467
|
Update shared/threat-models/codeql/threatmodels/ThreatModels.qll
Co-authored-by: Michael Nebel <michaelnebel@github.com>
|
2023-10-26 13:46:55 -04:00 |
|
Dave Bartolomeo
|
927eb8424d
|
Update shared/threat-models/codeql/threatmodels/ThreatModels.qll
Co-authored-by: Michael Nebel <michaelnebel@github.com>
|
2023-10-26 13:46:37 -04:00 |
|
Dave Bartolomeo
|
8d9e4d391f
|
Update shared/threat-models/codeql/threatmodels/ThreatModels.qll
Co-authored-by: Michael Nebel <michaelnebel@github.com>
|
2023-10-26 13:46:28 -04:00 |
|
Alexander Eyers-Taylor
|
55ec9d0a91
|
Merge pull request #14601 from aschackmull/java/fix-tests
Java: Update tests to new partial flow api
|
2023-10-26 17:52:01 +01:00 |
|
Alex Ford
|
5a1a3f0727
|
Ruby: modgen - deduplicate getAnyParameter logic
|
2023-10-26 17:45:47 +01:00 |
|
Alex Ford
|
86ba75cadf
|
Ruby: modgen - support self arguments
|
2023-10-26 17:42:46 +01:00 |
|
Alex Ford
|
6203887645
|
fixup
|
2023-10-26 17:38:43 +01:00 |
|
Mathias Vorreiter Pedersen
|
784bb72b33
|
Swift: Add some more tests.
|
2023-10-26 17:29:26 +01:00 |
|
Owen Mansel-Chan
|
b451adabfc
|
Two small QLDoc improvements
|
2023-10-26 17:10:12 +01:00 |
|
Owen Mansel-Chan
|
896a3c65be
|
Avoid doing float arithmetic with large integers
There is the possibility of overflow.
|
2023-10-26 17:09:53 +01:00 |
|
Owen Mansel-Chan
|
570ca3b6fe
|
Fix upper bound check to make test pass
|
2023-10-26 17:08:19 +01:00 |
|
Alex Ford
|
24946c0dfd
|
Ruby: modgen - restrict flow summaries to public methods
|
2023-10-26 17:05:31 +01:00 |
|
Alex Ford
|
fef2932f56
|
Apply suggestions from code review
Co-authored-by: Harry Maclean <hmac@github.com>
|
2023-10-26 17:04:51 +01:00 |
|
Owen Mansel-Chan
|
773f46d3b4
|
Add failing test for upper bound checks
|
2023-10-26 16:58:36 +01:00 |
|
Mathias Vorreiter Pedersen
|
30ecb4b0c8
|
Merge pull request #14588 from aschackmull/shared/rangeanalysis
C++/Java: Share core range analysis
|
2023-10-26 16:32:46 +01:00 |
|
yoff
|
867a39083e
|
Merge pull request #14114 from yoff/python/allow-namespace-packages
Python: Allow namespace packages
|
2023-10-26 16:56:05 +02:00 |
|
Tony Torralba
|
7af3d239ab
|
Java: Add JMS sink to java/unsafe-deserialization
|
2023-10-26 16:46:19 +02:00 |
|
Max Schaefer
|
08cc8b8e80
|
Autoformat.
|
2023-10-26 15:36:06 +01:00 |
|
erik-krogh
|
302199a74a
|
fix TypeExprKinds crashing on a ThisExpression
|
2023-10-26 16:33:54 +02:00 |
|
Max Schaefer
|
abef8483bd
|
Merge pull request #14600 from github/max-schaefer/express-rate-limit
JavaScript: Add support for importing `express-rate-limit` using a named import.
|
2023-10-26 15:15:22 +01:00 |
|
Max Schaefer
|
f42bd28ca9
|
Port changes to Ruby.
|
2023-10-26 15:06:45 +01:00 |
|
Mathias Vorreiter Pedersen
|
96a37f3a3c
|
Swift: Simplify more tests.
|
2023-10-26 14:55:17 +01:00 |
|
Max Schaefer
|
741735cc83
|
Port changes to JavaScript.
|
2023-10-26 14:47:24 +01:00 |
|
Mathias Vorreiter Pedersen
|
2ad121a8a5
|
Swift: Simplify test.
|
2023-10-26 14:46:59 +01:00 |
|
Rasmus Lerchedahl Petersen
|
dcc778520a
|
Python: refactor code
Also add explanatory comment.
Co-authored-by: Taus <tausbn@github.com>
|
2023-10-26 15:00:02 +02:00 |
|
Rasmus Lerchedahl Petersen
|
50041f07a3
|
Python: fix comment
|
2023-10-26 14:28:00 +02:00 |
|
Anders Schack-Mulligen
|
35f6e6ebb4
|
Java: Update tests to new partial flow api
|
2023-10-26 14:09:03 +02:00 |
|
Max Schaefer
|
aff848b038
|
Update javascript/ql/lib/semmle/javascript/security/dataflow/MissingRateLimiting.qll
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2023-10-26 13:06:52 +01:00 |
|
Jeroen Ketema
|
dbb4167f80
|
Merge pull request #14579 from jketema/ir-backwards
C++: Define an extractor version table and use in IR generation
|
2023-10-26 13:36:15 +02:00 |
|
Owen Mansel-Chan
|
0ed01453b9
|
Fix getMaxIntValue to accept bitSize 64
|
2023-10-26 12:27:43 +01:00 |
|
Max Schaefer
|
2c7291336d
|
Move test files into right directory.
|
2023-10-26 12:16:52 +01:00 |
|
Max Schaefer
|
bb146a1758
|
JavaScript: Add support for rateLimit export from express-rate-limit package.
|
2023-10-26 12:14:57 +01:00 |
|
Mathias Vorreiter Pedersen
|
2465cc20f0
|
Swift: Don't define 'ClosureSelfParameterNode' as the expression node of the closure.
|
2023-10-26 11:56:27 +01:00 |
|
Max Schaefer
|
3939167ba2
|
Include more details in the message for py/weak-cryptographic-algorithm.
Specifically, we add a link to the location where the cryptographic algorithm is configured, which can be far away from its use.
|
2023-10-26 11:28:09 +01:00 |
|
Jeroen Ketema
|
64004926bc
|
C++: Use a more declarative predicate name
|
2023-10-26 12:07:19 +02:00 |
|
Jeroen Ketema
|
903f376620
|
C++: Define an extractor version table and use in IR generation
|
2023-10-26 12:07:19 +02:00 |
|
Mathias Vorreiter Pedersen
|
b1d4ca505d
|
Merge pull request #14599 from aschackmull/dataflow/partialflow-separate
Dataflow: Restrict partial flow to either forward or reverse flow.
|
2023-10-26 11:01:03 +01:00 |
|
Anders Schack-Mulligen
|
bbc3cfba6f
|
Dataflow: Fix documentation.
|
2023-10-26 11:29:16 +02:00 |
|
Anders Schack-Mulligen
|
a2e3b37847
|
Dataflow: Fix accidental visibility.
|
2023-10-26 11:28:52 +02:00 |
|
Chris Smowton
|
8198898d73
|
Merge pull request #14583 from smowton/smowton/admin/really-deprecate-old-java-names
Java: Deprecate MethodAccess and SuperMethodAccess
|
2023-10-26 10:25:05 +01:00 |
|
Owen Mansel-Chan
|
39eeed9238
|
Add failing test showcasing problem
|
2023-10-26 10:20:27 +01:00 |
|
Stephan Brandauer
|
5fe6a5a730
|
Merge pull request #14487 from github/kaeluka/extraction-query-docs
Java: basic version of automodel extraction query docs
|
2023-10-26 11:10:01 +02:00 |
|