Raul Garcia (MSFT)
|
ef0d3720a1
|
Addressing a few comments
|
2021-02-10 13:39:24 -08:00 |
|
Raul Garcia
|
190164c182
|
Update csharp/ql/src/experimental/Security Features/campaign/Solorigate/Solorigate.qhelp
Co-authored-by: Bas van Schaik <5082246+sj@users.noreply.github.com>
|
2021-02-10 13:30:40 -08:00 |
|
Artem Smotrakov
|
af0f361ac8
|
Updated JexlInjection.ql to check for sandboxes
- Added a dataflow config to track setting a sandbox
on JexlBuilder
- Added SandboxedJexl3.java test
|
2021-02-10 22:19:45 +01:00 |
|
Erik Krogh Kristensen
|
7cff1f441b
|
add model for the unified and remark libraries
|
2021-02-10 18:13:01 +01:00 |
|
Rasmus Wriedt Larsen
|
c57a4df819
|
Python: Model taint of self.request on django view class
|
2021-02-10 17:48:48 +01:00 |
|
Rasmus Wriedt Larsen
|
9ca738d921
|
Python: Add taint test for self.request on django view class
|
2021-02-10 17:48:41 +01:00 |
|
Jonathan Leitschuh
|
3b92f97967
|
Refactor DeclaredRepository to library
|
2021-02-10 11:41:50 -05:00 |
|
Erik Krogh Kristensen
|
0d497e8b9a
|
add model for the showdown library
|
2021-02-10 17:22:42 +01:00 |
|
Anders Schack-Mulligen
|
e9bfbb677d
|
Java: Connect the external sources and steps to the defaults.
|
2021-02-10 17:06:21 +01:00 |
|
Anders Schack-Mulligen
|
5a391ab6c0
|
Java: Add qldoc.
|
2021-02-10 16:54:48 +01:00 |
|
Jonathan Leitschuh
|
21b6f35ddc
|
Update java/ql/src/Security/CWE/CWE-1104/MavenPomDependsOnBintray.qhelp
|
2021-02-10 10:52:27 -05:00 |
|
Jonathan Leitschuh
|
49985a77e3
|
Apply suggestions from code review
Co-authored-by: Marcono1234 <Marcono1234@users.noreply.github.com>
Co-authored-by: Owen Mansel-Chan <62447351+owen-mc@users.noreply.github.com>
|
2021-02-10 10:51:37 -05:00 |
|
Rasmus Wriedt Larsen
|
ca0d345987
|
Django: Model any class used in django route setup as view class
|
2021-02-10 16:26:25 +01:00 |
|
Rasmus Wriedt Larsen
|
b428945bc2
|
Django: Fix DjangoRouteHandler char-pred
Before it the class would contain _all_ functions xD
|
2021-02-10 16:21:51 +01:00 |
|
Rasmus Wriedt Larsen
|
78a3206fce
|
Python: Add test with unkown view class in django
|
2021-02-10 15:56:33 +01:00 |
|
Anders Schack-Mulligen
|
b74911204a
|
Merge pull request #4945 from intrigus-lgtm/java/insecure-jxbrowser
Java: Insecure JXBrowser
|
2021-02-10 15:48:17 +01:00 |
|
Rasmus Wriedt Larsen
|
42eceb80bd
|
Python: Handle view functions with decorators
|
2021-02-10 15:47:55 +01:00 |
|
Erik Krogh Kristensen
|
f76018c039
|
add taint step for the markdown-table library
|
2021-02-10 15:11:41 +01:00 |
|
Erik Krogh Kristensen
|
b4704f7016
|
add taint-step for the marked library
|
2021-02-10 14:51:08 +01:00 |
|
Erik Krogh Kristensen
|
91f7d33044
|
add change note
|
2021-02-10 14:17:49 +01:00 |
|
Erik Krogh Kristensen
|
101d4358a9
|
detect DOM nodes from event callbacks
|
2021-02-10 14:17:49 +01:00 |
|
Erik Krogh Kristensen
|
be9636491b
|
add source for react-hook-form in xss-through-dom
|
2021-02-10 14:17:49 +01:00 |
|
Erik Krogh Kristensen
|
65d93c9061
|
detect for DOM elements from DOM events in React
|
2021-02-10 14:17:49 +01:00 |
|
Erik Krogh Kristensen
|
458dda9d25
|
add xss-through-dom source from react-final-form
|
2021-02-10 14:17:49 +01:00 |
|
Erik Krogh Kristensen
|
ff3950ce98
|
add model for formik
|
2021-02-10 14:17:49 +01:00 |
|
Erik Krogh Kristensen
|
d1087d4e41
|
move sources from XssThroughDom into a customizations file
|
2021-02-10 14:17:49 +01:00 |
|
Erik Krogh Kristensen
|
4969a1ef4f
|
add change note
|
2021-02-10 14:16:31 +01:00 |
|
Erik Krogh Kristensen
|
0ca2310594
|
add model for htmlparser2
|
2021-02-10 14:16:31 +01:00 |
|
Erik Krogh Kristensen
|
e2a66bf3ed
|
add model for xml-js
|
2021-02-10 14:16:31 +01:00 |
|
Erik Krogh Kristensen
|
73f7cd149f
|
add model for sax
|
2021-02-10 14:16:31 +01:00 |
|
Erik Krogh Kristensen
|
c43025d7b3
|
add model for xml2js
|
2021-02-10 14:16:30 +01:00 |
|
Erik Krogh Kristensen
|
44ca2e26a6
|
add taint-step to XML parsers
|
2021-02-10 14:16:08 +01:00 |
|
intrigus
|
5c82ff83de
|
Java: Fix qhelp, fix CWE reference
|
2021-02-10 13:57:51 +01:00 |
|
Anders Schack-Mulligen
|
3a6fa9d99b
|
Java: Add support for framework modelling through csv data.
|
2021-02-10 13:25:03 +01:00 |
|
Alvaro Muñoz
|
645b021845
|
Add support for the Preconditions Class in the Guava framework
|
2021-02-10 13:20:29 +01:00 |
|
Alvaro Muñoz
|
0cf3a29429
|
Add support for Apache Commons Lang ArrayUtils
|
2021-02-10 13:09:57 +01:00 |
|
Shati Patel
|
18225fa254
|
Merge pull request #4997 from github/shati-patel/cwe-coverage-docs
Docs: Add outline for CWE coverage page
|
2021-02-10 11:45:09 +00:00 |
|
Alvaro Muñoz
|
3b4357792b
|
Remove sanitizing condition which does not prevent
vulnerability.
|
2021-02-10 12:21:48 +01:00 |
|
Anders Schack-Mulligen
|
66d0bf6b5e
|
Merge pull request #5128 from hvitved/dataflow/exploration-clears-content
Data flow: Take `clearsContent()` into account in flow exploration
|
2021-02-10 11:52:24 +01:00 |
|
yoff
|
9930d59aca
|
Merge pull request #5124 from RasmusWL/typetracking-with-decorator
Python: Add test for type-tracking through decorators
|
2021-02-10 09:34:54 +01:00 |
|
Tom Hvitved
|
1f9b42f9ab
|
Data flow: Sync files
|
2021-02-09 20:10:23 +01:00 |
|
Tom Hvitved
|
e5970f4c65
|
Data flow: Take clearsContent() into account in flow exploration
|
2021-02-09 20:09:24 +01:00 |
|
Geoffrey White
|
d475e55ec0
|
Update cpp/ql/test/README.md
Co-authored-by: hubwriter <hubwriter@github.com>
|
2021-02-09 15:20:03 +00:00 |
|
Geoffrey White
|
cc031118dd
|
Update CONTRIBUTING.md
Co-authored-by: hubwriter <hubwriter@github.com>
|
2021-02-09 15:19:30 +00:00 |
|
yo-h
|
e5331a4735
|
Java: accept changes in expected output
|
2021-02-09 09:17:35 -05:00 |
|
yo-h
|
e194411cfa
|
Java: fix javac errors in test code
|
2021-02-09 09:16:57 -05:00 |
|
luchua-bc
|
cb01613aa6
|
Exclude FP token patterns
|
2021-02-09 13:53:23 +00:00 |
|
Tamas Vajk
|
9854b95c30
|
Fix query performance
|
2021-02-09 14:45:22 +01:00 |
|
Alexander Eyers-Taylor
|
1c43505d30
|
Merge pull request #5121 from alexet/fix-js-jdoc
Javascript Extractor: Update <tt> tages to <code>
|
2021-02-09 13:07:19 +00:00 |
|
CodeQL CI
|
475d216f8e
|
Merge pull request #5087 from erik-krogh/immutable
Approved by asgerf
|
2021-02-09 12:43:19 +00:00 |
|