Geoffrey White
|
da06b2a615
|
C++: Improve Iterator.qll layout and QLDoc.
|
2021-02-12 14:54:46 +00:00 |
|
Geoffrey White
|
90dbbbb0c2
|
C++: Update Iterator.qll.
|
2021-02-12 14:54:46 +00:00 |
|
Geoffrey White
|
7705fc4f98
|
C++: Add more test cases for iterator taint flow.
|
2021-02-12 14:54:45 +00:00 |
|
Alvaro Muñoz
|
7d294361dc
|
Update java/ql/src/semmle/code/java/frameworks/apache/Lang.qll
Co-authored-by: Joe Farebrother <joefarebrother@github.com>
|
2021-02-12 15:40:44 +01:00 |
|
Alvaro Muñoz
|
6b80a42913
|
apply LSP formatter and add missing dot
|
2021-02-12 15:03:11 +01:00 |
|
Alvaro Muñoz
|
8606386c2c
|
add bidirectional import
|
2021-02-12 14:59:28 +01:00 |
|
Alvaro Muñoz
|
49eda8ced6
|
apply LSP formatter
|
2021-02-12 14:56:10 +01:00 |
|
Anders Schack-Mulligen
|
085286ab58
|
Merge pull request #5135 from pwntester/guava_preconditions
Add support for the Preconditions Class in the Guava framework
|
2021-02-12 14:15:17 +01:00 |
|
Chris Smowton
|
655cfb3a47
|
Re-introduce deprecated versions of old Maven predicate names
|
2021-02-12 12:24:19 +00:00 |
|
Chris Smowton
|
97df60f9d6
|
Move misplaced experimental query into the conventional directory
|
2021-02-12 12:12:16 +00:00 |
|
Chris Smowton
|
942ae7ef47
|
Merge pull request #5142 from Marcono1234/marcono1234/maven-pom-improvements
Java: Improve MavenPom documentation, rename inconsistent predicates
|
2021-02-12 11:52:19 +00:00 |
|
Rasmus Wriedt Larsen
|
10fdc4bfb9
|
Python: Add support for more yaml loading functions
|
2021-02-12 12:30:00 +01:00 |
|
Rasmus Wriedt Larsen
|
2021cdbe33
|
Python: Add tests for more yaml loading functions
|
2021-02-12 12:30:00 +01:00 |
|
Rasmus Wriedt Larsen
|
f328e84bd2
|
Python: Mention yaml.safe_load in the qhelp
|
2021-02-12 12:29:55 +01:00 |
|
Rasmus Wriedt Larsen
|
1651f81ac8
|
Python: Refactor to avoid confusing name
After discussion with @yoff
|
2021-02-12 12:19:37 +01:00 |
|
Mathias Vorreiter Pedersen
|
729c7f2371
|
C++: Add deprecated alias to RemoteFlowSourceFunction and LocalFlowSourceFunction.
|
2021-02-12 10:53:34 +01:00 |
|
Mathias Vorreiter Pedersen
|
b1c7cb6396
|
C++: Address review comments.
|
2021-02-12 10:37:27 +01:00 |
|
Rasmus Wriedt Larsen
|
ed2dc5f6ad
|
Python: Fix date for change-note
|
2021-02-12 10:26:31 +01:00 |
|
Tamas Vajk
|
0aded1549e
|
Improve NestedLoopsSameVariable query performance
|
2021-02-12 09:33:33 +01:00 |
|
Rasmus Lerchedahl Petersen
|
cfa72af12c
|
Python: Update test expectation to new format
|
2021-02-12 09:30:12 +01:00 |
|
Marcono1234
|
905648e452
|
Add ConditionalExpr.getBranchExpr(boolean)
|
2021-02-12 04:50:41 +01:00 |
|
haby0
|
6901cd4899
|
Merge branch 'main' of https://github.com/haby0/codeql into main
|
2021-02-12 11:18:33 +08:00 |
|
haby0
|
22e741c7a3
|
*)add XQExpression.executeCommand(0) sink
|
2021-02-12 11:17:42 +08:00 |
|
haby0
|
dbb3d458f5
|
*)add XQExpression.executeCommand(0) sink
|
2021-02-12 10:47:41 +08:00 |
|
Marcono1234
|
e89891fa1f
|
Address review comments
|
2021-02-12 01:30:47 +01:00 |
|
Artem Smotrakov
|
042c0b005e
|
Covered sandboxes for JEXL 2
- Updated SandboxedJexlFlowConfig to cover JEXL 2
- Added SandboxedJexl2 test
|
2021-02-11 22:57:26 +01:00 |
|
Raul Garcia (MSFT)
|
710ca21d19
|
Addressing comments we missed earlier
|
2021-02-11 11:52:58 -08:00 |
|
Artem Smotrakov
|
7543df60da
|
Callable.call() should not be a sink in JexlInjection.ql
|
2021-02-11 20:37:23 +01:00 |
|
Geoffrey White
|
354f21f2c3
|
C++: BSL support.
|
2021-02-11 16:57:20 +00:00 |
|
Erik Krogh Kristensen
|
004147a22f
|
add change note
|
2021-02-11 17:54:53 +01:00 |
|
Erik Krogh Kristensen
|
6f405635ef
|
add ClientRequest model for apollo-client
|
2021-02-11 17:49:44 +01:00 |
|
Mathias Vorreiter Pedersen
|
91627cbd88
|
C++: Add models for BSD-style send and recv functions.
|
2021-02-11 17:21:32 +01:00 |
|
Geoffrey White
|
21b2999722
|
C++: Update StdSet.qll.
|
2021-02-11 16:01:55 +00:00 |
|
Geoffrey White
|
33b5802ff6
|
C++: Update StdPair.qll (just for consistency).
|
2021-02-11 16:01:44 +00:00 |
|
Erik Krogh Kristensen
|
fd46b7a7bc
|
fix type in change-note
Co-authored-by: intrigus-lgtm <60750685+intrigus-lgtm@users.noreply.github.com>
|
2021-02-11 16:17:26 +01:00 |
|
Erik Krogh Kristensen
|
69d8aa143c
|
add taint step for the snarkdown libary
|
2021-02-11 16:16:46 +01:00 |
|
Taus Brock-Nannestad
|
4c66071f5f
|
Python: Revert "Python: Support moduleImport("dotted.name") in API graphs"
This reverts commit 2c4a477a4e.
It's probably best _not_ to do this, as any `getMember` cycle in the
API graph will lead to nontermination.
|
2021-02-11 16:08:28 +01:00 |
|
Taus Brock-Nannestad
|
ea30598a08
|
Python: Split dotted names more efficiently
|
2021-02-11 16:07:39 +01:00 |
|
Jonathan Leitschuh
|
35e2ceba13
|
Update java/ql/src/semmle/code/xml/MavenPom.qll
Co-authored-by: Marcono1234 <Marcono1234@users.noreply.github.com>
|
2021-02-11 08:59:02 -05:00 |
|
Erik Krogh Kristensen
|
d14586de56
|
add two non ReDoS regular expressions to the ReDoS test suite
Adds the regular expression from #5145
|
2021-02-11 14:41:45 +01:00 |
|
Erik Krogh Kristensen
|
f12c38425f
|
add change-note
|
2021-02-11 13:36:53 +01:00 |
|
Erik Krogh Kristensen
|
3ee0029cd8
|
Update javascript/change-notes/2021-02-08-xml-parser-taint.md
Co-authored-by: Asger F <asgerf@github.com>
|
2021-02-11 13:33:42 +01:00 |
|
CodeQL CI
|
02578cfff2
|
Merge pull request #5112 from erik-krogh/forms
Approved by asgerf
|
2021-02-11 04:32:14 -08:00 |
|
Erik Krogh Kristensen
|
044f80215e
|
add change note
|
2021-02-11 09:34:04 +01:00 |
|
Erik Krogh Kristensen
|
010d580f8e
|
add model for multiparty
|
2021-02-11 09:34:04 +01:00 |
|
Erik Krogh Kristensen
|
61b4ffec3d
|
add remote flow from the Formidable library
|
2021-02-11 09:34:04 +01:00 |
|
Erik Krogh Kristensen
|
a03f4ed3cd
|
add remote flow source for busboy
|
2021-02-11 09:34:02 +01:00 |
|
Erik Krogh Kristensen
|
e2fbf8a68c
|
add files uploaded with multer as RemoteFlowSource
|
2021-02-11 09:33:15 +01:00 |
|
haby0
|
a6a0fa28c4
|
*)add XQExpression.executeQuery(0) sink
|
2021-02-11 16:05:48 +08:00 |
|
Marcono1234
|
2a1c11b517
|
Improve MavenPom documentation, rename inconsistent predicates
|
2021-02-10 23:56:45 +01:00 |
|