Joe Farebrother
|
38072c7863
|
Fix typo
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
|
2025-06-02 16:42:27 +01:00 |
|
Napalys Klicius
|
3cbc4142f0
|
Update javascript/ql/src/Quality/UnhandledStreamPipe.ql
Co-authored-by: Asger F <asgerf@github.com>
|
2025-06-02 17:40:06 +02:00 |
|
Napalys Klicius
|
aed9e9c883
|
Merge pull request #19634 from Napalys/js/url_obj_propagation
JS: Add URL constructor taint tracking for request forgery
|
2025-06-02 17:32:44 +02:00 |
|
Paolo Tranquilli
|
baac2eecb0
|
Ripunzip: update default workflow versions
|
2025-06-02 17:30:34 +02:00 |
|
Paolo Tranquilli
|
b1afa6681c
|
CI: remove deprecated windows-2019 usage
|
2025-06-02 17:26:42 +02:00 |
|
Nicolas Will
|
5a822462ad
|
Merge branch 'main' into openssl_keyagreement_instances_and_consumers
|
2025-06-02 16:54:22 +02:00 |
|
Nicolas Will
|
806fc6ae6a
|
Merge pull request #19564 from bdrodes/initial_openssl_tests
Quantum: Add initial qltests for OpenSSL modeling
|
2025-06-02 16:52:27 +02:00 |
|
Arthur Baars
|
ae0c547e89
|
Rust: fix CFG for MacroPat
|
2025-06-02 16:37:55 +02:00 |
|
REDMOND\brodes
|
f5d24c5a7b
|
Crypto: Fix UnknownKeyAgreementType to OthernKeyAgreementType for JCA.
|
2025-06-02 10:11:53 -04:00 |
|
REDMOND\brodes
|
a473c96a9c
|
Crypto: Move crypto test stubs under experimental/stubs and remove special CODEOWNERS assignments for crypto stubs.
|
2025-06-02 16:10:35 +02:00 |
|
REDMOND\brodes
|
6b267479be
|
Crypto: Update crypto stubs location under 'crypto' and associate codeowners on any test/stubs/crypto. Minor fix to HashAlgorithmValueConsumer (remove library detector logic).
|
2025-06-02 16:10:35 +02:00 |
|
REDMOND\brodes
|
a9bdcc72eb
|
Crypto: Move openssl stubs to a shared stubs location. Include openssl apache license and a readme for future stub creation. Modify existing test case to reference stubs location.
|
2025-06-02 16:10:35 +02:00 |
|
REDMOND\brodes
|
0de6647927
|
Crypto: Adding initial openssl tests, fixing a bug in hash modeling found through tests, and updating CODEOWNERS for quantum tests
|
2025-06-02 16:10:35 +02:00 |
|
Arthur Baars
|
5c21c01ad0
|
Update rust/ql/src/queries/summary/Stats.qll
|
2025-06-02 15:42:43 +02:00 |
|
Fredrik Dahlgren
|
d0739b21e5
|
Restricted signature input nodes to verify nodes
|
2025-06-02 15:37:33 +02:00 |
|
Paolo Tranquilli
|
dfc03cbad1
|
Merge branch 'main' into redsun82/rust-extract-libs
|
2025-06-02 15:33:53 +02:00 |
|
Joe Farebrother
|
57a0c7a1ab
|
Performance fix - Use basic blocks instead of full cfg reachability.
|
2025-06-02 14:33:52 +01:00 |
|
Napalys Klicius
|
1f256ab71e
|
Added change note
|
2025-06-02 14:59:43 +02:00 |
|
Napalys Klicius
|
bca1bc7153
|
JS: Enhance isDomProperty to check for getAPropertyRead on DOM nodes
|
2025-06-02 14:56:45 +02:00 |
|
Napalys Klicius
|
9b2ef8be10
|
JS: add test for DOM access where expression appears to have no side effects
|
2025-06-02 14:54:46 +02:00 |
|
Michael Nebel
|
21cb8b2172
|
Merge pull request #19638 from martincostello/dotnet-branding
Fix user-facing casing of NuGet
|
2025-06-02 14:06:35 +02:00 |
|
Taus
|
9fe031d8eb
|
Merge pull request #19594 from sylwia-budzynska/pandas-sqli
Python: Add Pandas SQLi sinks
|
2025-06-02 13:40:14 +02:00 |
|
Napalys Klicius
|
c981c4fe30
|
Update javascript/ql/lib/change-notes/2025-05-30-url-package-taint-step.md
Co-authored-by: Asger F <asgerf@github.com>
|
2025-06-02 13:34:47 +02:00 |
|
Tom Hvitved
|
bf39058573
|
Merge pull request #19611 from hvitved/rust/path-resolution-std-prelude
Rust: Also take the `std` prelude into account when resolving paths
|
2025-06-02 13:04:57 +02:00 |
|
Paolo Tranquilli
|
2561f3c081
|
Merge pull request #19585 from github/redsun82/rust-skip-unexpanded-in-libraries
Rust: skip unexpanded stuff in library emission
|
2025-06-02 12:10:37 +02:00 |
|
Napalys Klicius
|
298ef9ab12
|
Now able to track error handler registration via instance properties
|
2025-06-02 11:01:41 +02:00 |
|
Martin Costello
|
77a6a2d442
|
Fix user-facing casing of NuGet
Fix user-facing strings to use "NuGet" instead of "Nuget" and "dotnet" instead of "Dotnet".
|
2025-06-02 09:30:16 +01:00 |
|
Paolo Tranquilli
|
fa3fcf0f95
|
Rust: skip all token trees in library mode
|
2025-06-02 09:32:39 +02:00 |
|
Paolo Tranquilli
|
7be44d2fe8
|
Merge branch 'main' into redsun82/rust-skip-unexpanded-in-libraries
|
2025-06-02 09:27:56 +02:00 |
|
Arthur Baars
|
943dd8e70c
|
update output
|
2025-05-30 22:56:06 +02:00 |
|
Arthur Baars
|
c44a7c3036
|
Rust: codegen
|
2025-05-30 22:56:04 +02:00 |
|
Arthur Baars
|
0c8e886821
|
Rust: fix QLdoc examples
|
2025-05-30 22:55:50 +02:00 |
|
Napalys Klicius
|
0b6a747737
|
Added change note
|
2025-05-30 18:33:59 +02:00 |
|
Napalys Klicius
|
b9b62fa1c1
|
JS: Add URL from url package constructor taint step for request forgery detection
|
2025-05-30 18:32:02 +02:00 |
|
Napalys Klicius
|
19cc3e335f
|
JS: Add test case for RequestForgery with url wrapped via package URL
|
2025-05-30 18:26:47 +02:00 |
|
Napalys Klicius
|
f843cc02f6
|
Fix false positives in stream pipe analysis by improving error handler tracking via property access.
|
2025-05-30 18:08:04 +02:00 |
|
REDMOND\brodes
|
cf015d18f1
|
Crypto: Add openssl key agreement instances and consumers (KEM and KEY_EXCH). Fix for raw algorithm names in all current instances. Update constants to include key agreement algorithms, previously missing. Note added in model for the possibility of ESDH.
|
2025-05-30 11:29:34 -04:00 |
|
Mathias Vorreiter Pedersen
|
f6231a37e1
|
Merge pull request #19627 from MathiasVP/generalize-bulk-generation
Bulk MAD generator: Support databases from DCA runs
|
2025-05-30 14:46:36 +01:00 |
|
REDMOND\brodes
|
69e3a20e24
|
Crypto: Update crypto stubs location under 'crypto' and associate codeowners on any test/stubs/crypto. Minor fix to HashAlgorithmValueConsumer (remove library detector logic).
|
2025-05-30 09:35:33 -04:00 |
|
Mathias Vorreiter Pedersen
|
7cb9024cc6
|
Bulk generator: Flip default values for summaries, sources, and sinks.
|
2025-05-30 13:33:24 +01:00 |
|
Mathias Vorreiter Pedersen
|
0f30644afd
|
Bulk generator: Snake case things.
|
2025-05-30 13:26:53 +01:00 |
|
Mathias Vorreiter Pedersen
|
3444c986ec
|
Bulk generator: Fix field name.
|
2025-05-30 13:25:12 +01:00 |
|
Mathias Vorreiter Pedersen
|
bdf411afbc
|
Bulk generator: Make 'database_results' a map to simplify away the explicit sorting.
|
2025-05-30 13:09:55 +01:00 |
|
Mathias Vorreiter Pedersen
|
cdd869a970
|
Bulk generator: Autoformat.
|
2025-05-30 12:49:12 +01:00 |
|
Mathias Vorreiter Pedersen
|
3ddca32705
|
Update misc/scripts/models-as-data/bulk_generate_mad.py
Co-authored-by: Simon Friis Vindum <paldepind@github.com>
|
2025-05-30 12:48:50 +01:00 |
|
Mathias Vorreiter Pedersen
|
7c2612a6a1
|
Bulk generator: Specify a path to the PAT instead of the PAT itself.
|
2025-05-30 12:47:07 +01:00 |
|
Mathias Vorreiter Pedersen
|
1228080914
|
Bulk generator: Specify 'language' in the config file.
|
2025-05-30 12:40:21 +01:00 |
|
Mathias Vorreiter Pedersen
|
fc165db8ac
|
Bulk generator: Specify 'with-summaries', 'with-sources', and 'with-sinks' in the config file.
|
2025-05-30 12:40:20 +01:00 |
|
Mathias Vorreiter Pedersen
|
7121f5c57e
|
Bulk generator: Use the 'Project' type throughout the file.
|
2025-05-30 12:08:42 +01:00 |
|
Arthur Baars
|
0157c16008
|
Rust: delete empty expected file
|
2025-05-30 12:57:45 +02:00 |
|