Geoffrey White
|
a6937beee3
|
Merge branch 'main' into sqltaint
|
2021-01-08 17:27:43 +00:00 |
|
Shati Patel
|
b794fcb841
|
Merge pull request #4925 from shati-patel/fix-links
Fix broken links in CodeQL documentation
|
2021-01-08 16:35:15 +00:00 |
|
Shati Patel
|
53c46edc1c
|
Address review comments
|
2021-01-08 15:20:40 +00:00 |
|
Rasmus Wriedt Larsen
|
00c253a710
|
Java: Don't ignore local taint steps (fixup)
|
2021-01-08 15:29:01 +01:00 |
|
Anders Schack-Mulligen
|
e5b4975450
|
Merge pull request #4675 from luchua-bc/cleartext-storage-shared-prefs
Java: Query to detect cleartext storage of sensitive information using Android SharedPreferences
|
2021-01-08 12:41:34 +01:00 |
|
Tamás Vajk
|
136e5c93d1
|
Merge pull request #4672 from tamasvajk/feature/extract-anon-types
C#: Extract anonymous types explicitly
|
2021-01-08 11:54:37 +01:00 |
|
CodeQL CI
|
807fc94627
|
Merge pull request #4921 from erik-krogh/moreShellSan
Approved by esbena
|
2021-01-08 00:58:26 -08:00 |
|
Tamas Vajk
|
800fd94572
|
Add DB upgrade folder
|
2021-01-08 08:20:49 +01:00 |
|
Tamas Vajk
|
056dbe31d5
|
C#: Remove throw completion from StringLiteral
|
2021-01-08 08:14:08 +01:00 |
|
Erik Krogh Kristensen
|
6423c32990
|
Update javascript/ql/src/semmle/javascript/security/dataflow/UnsafeShellCommandConstructionCustomizations.qll
Co-authored-by: Esben Sparre Andreasen <esbena@github.com>
|
2021-01-07 22:02:39 +01:00 |
|
Shati Patel
|
cdcb4a9599
|
Fix redirects from Sphinx linkcheck
|
2021-01-07 15:45:40 +00:00 |
|
Shati Patel
|
3da66b7fd9
|
Fix broken links from Sphinx linkcheck
|
2021-01-07 15:45:28 +00:00 |
|
Tamas Vajk
|
f971f42bb1
|
Add new stats file
|
2021-01-07 15:24:10 +01:00 |
|
Tamas Vajk
|
fdf5cf9dd0
|
C#: Extract anonymous types explicitly
|
2021-01-07 15:24:10 +01:00 |
|
Tom Hvitved
|
63f76b1b43
|
C#: Uniform treatment of all SSA definitions
|
2021-01-07 15:16:44 +01:00 |
|
Tom Hvitved
|
8d77f4bac9
|
C#: Remove ImplicitUntrackedDefinition
|
2021-01-07 15:16:39 +01:00 |
|
luchua-bc
|
606d0946fc
|
Update qldoc
|
2021-01-07 14:05:12 +00:00 |
|
Tamás Vajk
|
3b16d2689d
|
Merge pull request #4821 from tamasvajk/feature/csharp9-cil-init-prop
C#: Extract init only accessors from CIL
|
2021-01-07 15:04:40 +01:00 |
|
CodeQL CI
|
c193d9f375
|
Merge pull request #4823 from erik-krogh/furtherReDoS
Approved by esbena
|
2021-01-07 05:24:07 -08:00 |
|
Erik Krogh Kristensen
|
7eab08511b
|
add source code examples to blocksCharInAccess
|
2021-01-07 13:58:26 +01:00 |
|
Erik Krogh Kristensen
|
8b03ab0c01
|
update docstring for getAShellChar
Co-authored-by: Esben Sparre Andreasen <esbena@github.com>
|
2021-01-07 13:58:26 +01:00 |
|
Erik Krogh Kristensen
|
2aa59a3f8b
|
support sanitizers that sanitize individual chars in js/shell-command-constructed-from-input
|
2021-01-07 13:58:25 +01:00 |
|
Mathias Vorreiter Pedersen
|
13a67c906e
|
Merge pull request #4810 from geoffw0/multtoalloc
C++: Query for multiplications used in allocations.
|
2021-01-07 13:48:58 +01:00 |
|
luchua-bc
|
b54e5b1c49
|
Revamp the library module
|
2021-01-07 12:44:59 +00:00 |
|
ihsinme
|
2d6dafc6be
|
Update MemoryLeakOnFailedCallToRealloc.ql
|
2021-01-07 15:44:50 +03:00 |
|
ihsinme
|
f378c14659
|
Update MemoryLeakOnFailedCallToRealloc.expected
|
2021-01-07 15:43:58 +03:00 |
|
ihsinme
|
592cd284e8
|
Update test.c
|
2021-01-07 15:41:31 +03:00 |
|
CodeQL CI
|
7db5a999e9
|
Merge pull request #4919 from erik-krogh/revertSum
Approved by esbena
|
2021-01-07 03:55:14 -08:00 |
|
Tamás Vajk
|
6cbff13778
|
Merge pull request #4905 from tamasvajk/fix/attribute-argument-extraction
C#: Fix attribute argument extraction
|
2021-01-07 12:28:43 +01:00 |
|
Erik Krogh Kristensen
|
7e21081b70
|
add comment about regexp detected by js/polynomial-redos
|
2021-01-07 12:06:12 +01:00 |
|
Alexander Eyers-Taylor
|
4100973d17
|
Merge pull request #4914 from alexet/fix-spec-bugs
QL Language specification. Fix multiple spec bugs.
|
2021-01-07 10:56:53 +00:00 |
|
Tamas Vajk
|
e00db46d60
|
Minor code quality improvements
|
2021-01-07 09:19:13 +01:00 |
|
Tom Hvitved
|
2c09f9a8f2
|
Merge pull request #4903 from hvitved/csharp/ssa-fast-tc
C#: Port SSA performance improvements from Java
|
2021-01-07 09:17:21 +01:00 |
|
Erik Krogh Kristensen
|
bfd8d1b1e9
|
Merge branch 'main' into revertSum
|
2021-01-06 23:04:08 +01:00 |
|
ihsinme
|
abdeaabd77
|
Update MemoryLeakOnFailedCallToRealloc.ql
|
2021-01-06 22:46:03 +03:00 |
|
ihsinme
|
2b8227e04d
|
Update cpp/ql/src/experimental/Security/CWE/CWE-401/MemoryLeakOnFailedCallToRealloc.ql
Co-authored-by: Geoffrey White <40627776+geoffw0@users.noreply.github.com>
|
2021-01-06 22:23:46 +03:00 |
|
ihsinme
|
f7eb328f76
|
Update cpp/ql/src/experimental/Security/CWE/CWE-401/MemoryLeakOnFailedCallToRealloc.qhelp
Co-authored-by: Geoffrey White <40627776+geoffw0@users.noreply.github.com>
|
2021-01-06 22:18:14 +03:00 |
|
ihsinme
|
d7f31ca1a0
|
Update cpp/ql/src/experimental/Security/CWE/CWE-401/MemoryLeakOnFailedCallToRealloc.qhelp
Co-authored-by: Geoffrey White <40627776+geoffw0@users.noreply.github.com>
|
2021-01-06 22:17:26 +03:00 |
|
CodeQL CI
|
9d4cd0aa85
|
Merge pull request #4862 from erik-krogh/shellSanitizer
Approved by esbena
|
2021-01-06 11:16:12 -08:00 |
|
Geoffrey White
|
b5bcbd303e
|
C++: Cleaner solution.
|
2021-01-06 18:22:31 +00:00 |
|
Geoffrey White
|
f69ceb3dbb
|
Merge pull request #4904 from MathiasVP/conflated-dataflow-testcases
C++: Add dataflow testcases that need flow through conflated memory
|
2021-01-06 17:48:18 +00:00 |
|
luchua-bc
|
f13b8814f5
|
Update class/method names in the module
|
2021-01-06 16:49:35 +00:00 |
|
luchua-bc
|
5690bf49f4
|
Optimize the query
|
2021-01-06 16:21:26 +00:00 |
|
Alexander Eyers-Taylor
|
2686335531
|
Merge pull request #1 from shati-patel/fix-spec-bugs-edits
Editorial review for QL language updates
|
2021-01-06 14:48:26 +00:00 |
|
Erik Krogh Kristensen
|
f1cee70e82
|
add class-field flowstep to js/shell-command-constructed-from-input
|
2021-01-06 14:37:00 +01:00 |
|
Tamas Vajk
|
04074c425b
|
C#: Fix named attribute argument extraction
|
2021-01-06 14:27:36 +01:00 |
|
Tamas Vajk
|
44372f4db7
|
C#: Fix attribute argument extraction when default argument value is present
|
2021-01-06 14:27:36 +01:00 |
|
Tamas Vajk
|
6d95ad3282
|
C#: Add file instead of generated location for extraction errors when possible
|
2021-01-06 14:27:31 +01:00 |
|
Shati Patel
|
bc6b1e8ed7
|
Fix typos and small formatting bugs
|
2021-01-06 12:11:16 +00:00 |
|
Geoffrey White
|
81205f37c5
|
C++: Fix test annotation.
|
2021-01-06 11:45:17 +00:00 |
|