Rasmus Lerchedahl Petersen
|
375da38765
|
Python: Minimal compilation of shared dataflow
|
2020-06-12 11:48:41 +02:00 |
|
Erik Krogh Kristensen
|
f0ec2eb37b
|
add missing qldoc
|
2020-06-12 11:47:53 +02:00 |
|
Erik Krogh Kristensen
|
c9fc1a378d
|
Merge pull request #3663 from erik-krogh/bad-crypto
JS: Introduce query to detect biased random number generators
|
2020-06-12 11:32:12 +02:00 |
|
Erik Krogh Kristensen
|
1751fb6c47
|
add missing qldoc
|
2020-06-12 11:30:22 +02:00 |
|
Erik Krogh Kristensen
|
adabd2daca
|
add qldoc and customizations module
|
2020-06-12 11:26:49 +02:00 |
|
Asger Feldthaus
|
4c536dde20
|
JS: Propagate locally returned functions out of calls
|
2020-06-12 10:07:37 +01:00 |
|
Erik Krogh Kristensen
|
908edb39b9
|
unsecure -> insecure
|
2020-06-12 11:02:26 +02:00 |
|
Erik Krogh Kristensen
|
86b23b239e
|
Merge pull request #3656 from erik-krogh/destruct-yargs
JS: support rest-patterns inside property patterns
|
2020-06-12 10:57:24 +02:00 |
|
Asger Feldthaus
|
6531db3cca
|
JS: Add test
|
2020-06-12 09:56:38 +01:00 |
|
Erik Krogh Kristensen
|
57d2226080
|
typo
|
2020-06-12 10:55:29 +02:00 |
|
Erik Krogh Kristensen
|
9780fcf8fe
|
fix ftp protocol regexp
|
2020-06-12 10:54:56 +02:00 |
|
Erik Krogh Kristensen
|
3f957103ed
|
improve alert message - and autoformat
|
2020-06-12 10:53:19 +02:00 |
|
Erik Krogh Kristensen
|
056a7e87ff
|
refactor into customizations module - and move curl download to a ClientRequest
|
2020-06-12 10:51:09 +02:00 |
|
Erik Krogh Kristensen
|
8225adcaea
|
move TODOs
|
2020-06-12 10:28:06 +02:00 |
|
Erik Krogh Kristensen
|
02c4a0477d
|
add tests for js/build-artifact-leak
|
2020-06-12 10:21:37 +02:00 |
|
Anders Schack-Mulligen
|
041af38934
|
Merge pull request #3697 from intrigus-lgtm/patch-1
Fix typo
|
2020-06-12 10:04:40 +02:00 |
|
semmle-qlci
|
6f40fc2eae
|
Merge pull request #3678 from Marcono1234/patch-1
Approved by shati-patel
|
2020-06-12 08:49:53 +01:00 |
|
Anders Schack-Mulligen
|
421a548e42
|
Update java/ql/src/semmle/code/java/Expr.qll
|
2020-06-12 09:24:37 +02:00 |
|
Jonas Jensen
|
abd05bcff1
|
Merge pull request #3596 from robertbrignull/more-suites
Add more code-scanning suites
|
2020-06-12 09:08:20 +02:00 |
|
semmle-qlci
|
035d8ea24c
|
Merge pull request #3690 from asger-semmle/js/fix-lgtm-filters-comment
Approved by max-schaefer
|
2020-06-12 07:40:58 +01:00 |
|
Esben Sparre Andreasen
|
1bdae109c5
|
Merge pull request #3686 from esbena/js/insecure-http-options
JS: add query js/disabling-certificate-validation
|
2020-06-12 08:40:12 +02:00 |
|
semmle-qlci
|
5c2f1169d0
|
Merge pull request #3679 from asger-semmle/js/dom-value-ref-restriction
Approved by erik-krogh, esbena
|
2020-06-12 07:39:26 +01:00 |
|
Esben Sparre Andreasen
|
243e3ad9e3
|
Merge pull request #3672 from esbena/js/server-crashing-route-handler
JS: add initial version of ServerCrash.ql
|
2020-06-12 08:38:37 +02:00 |
|
Robert Marsh
|
65f4ef712e
|
C++: accept false positive tests after merge
The IR false positives are due to the same path length limit as the AST
false positives on the same line.
|
2020-06-11 15:27:13 -07:00 |
|
Erik Krogh Kristensen
|
5b491313ad
|
add simple query for detecting sensitive files downloaded over unsecure connection
|
2020-06-11 23:19:28 +02:00 |
|
Erik Krogh Kristensen
|
065cb04202
|
make PropNode private again
|
2020-06-11 23:19:03 +02:00 |
|
Erik Krogh Kristensen
|
ef72c03ca9
|
use simpler taint-step for DestructingPattern
|
2020-06-11 23:16:46 +02:00 |
|
Marcono1234
|
7cd6dd27a6
|
Add link to Java regex Pattern documentation to language.rst
Co-authored-by: Shati Patel <42641846+shati-patel@users.noreply.github.com>
|
2020-06-11 23:02:59 +02:00 |
|
intrigus-lgtm
|
422b059aec
|
Fix typo
|
2020-06-11 22:54:13 +02:00 |
|
Robert Marsh
|
a7efa0d602
|
Merge branch 'master' into ir-this-parameter-2
|
2020-06-11 13:21:52 -07:00 |
|
Mathias Vorreiter Pedersen
|
b78c06559e
|
Merge pull request #3691 from geoffw0/reftest
C++: Add a test case for CWE-114 involving pointers and references.
|
2020-06-11 22:02:45 +02:00 |
|
Geoffrey White
|
fdd7ad2300
|
C++: Add a SideEffectFunction model to 'system'.
|
2020-06-11 18:59:17 +01:00 |
|
Geoffrey White
|
e8b34e07f8
|
C++: Add an AliasFunction model to 'system'.
|
2020-06-11 18:44:41 +01:00 |
|
Geoffrey White
|
7fee2c239d
|
C++: Add an ArrayFunction model to 'system'.
|
2020-06-11 18:44:09 +01:00 |
|
Geoffrey White
|
b38a7a9ffc
|
C++: Fill out ArrayFunction model for 'fgets'.
|
2020-06-11 18:20:24 +01:00 |
|
Robert Marsh
|
ae46a8d8a1
|
Merge pull request #3692 from igfoo/blockstmt
C++: Fix reference to `Block`
|
2020-06-11 09:49:19 -07:00 |
|
Geoffrey White
|
40c20f2731
|
C++: Add the test for DefaultTaintTracking as well.
|
2020-06-11 17:37:05 +01:00 |
|
Geoffrey White
|
2f192f6a0c
|
C++: Add a test of char* -> std::string -> char* taint.
|
2020-06-11 17:37:05 +01:00 |
|
Dave Bartolomeo
|
41df7000c5
|
Merge from master, including fixing up merge conflicts
|
2020-06-11 12:20:46 -04:00 |
|
Ian Lynagh
|
fd88289e46
|
C++: Fix reference to Block
We don't call it `BlockStmt`.
|
2020-06-11 16:50:23 +01:00 |
|
Asger Feldthaus
|
475c631ff9
|
JS: Fix a misleading javadoc comment
|
2020-06-11 16:16:51 +01:00 |
|
Dave Bartolomeo
|
b116a3e8ea
|
C#: Rename IR module references to point to experimental
|
2020-06-11 10:24:01 -04:00 |
|
Anders Schack-Mulligen
|
c961a31789
|
Java: Add Expr.getAnEnclosingStmt.
|
2020-06-11 13:46:12 +02:00 |
|
semmle-qlci
|
c2de54f5ca
|
Merge pull request #3685 from shati-patel/ast-go-edits
Approved by felicitymay, owen-mc
|
2020-06-11 12:43:20 +01:00 |
|
Esben Sparre Andreasen
|
169c8909df
|
formatting
|
2020-06-11 13:28:26 +02:00 |
|
Esben Sparre Andreasen
|
bc7f02156b
|
JS: replace class with two predicates (and improve alert message)
|
2020-06-11 13:20:46 +02:00 |
|
Erik Krogh Kristensen
|
7c7af8d841
|
less heuristics when flagging division that is rounded
|
2020-06-11 12:55:13 +02:00 |
|
Erik Krogh Kristensen
|
f1b24ba901
|
use type inference to detect string concatenations
|
2020-06-11 12:34:58 +02:00 |
|
Esben Sparre Andreasen
|
2e059376fd
|
JS: add query js/disabling-certificate-validation
|
2020-06-11 12:32:01 +02:00 |
|
Erik Krogh Kristensen
|
f634c62af5
|
remove redundant check
|
2020-06-11 12:18:41 +02:00 |
|