Mathias Vorreiter Pedersen
|
cca77ed65c
|
Merge branch 'main' into add-return-value-deref-to-model-util
|
2021-10-01 22:02:06 +02:00 |
|
Geoffrey White
|
b9a1a451a9
|
C++: Autoformat.
|
2021-10-01 19:21:30 +01:00 |
|
Tamás Vajk
|
62aa7b75bd
|
Merge pull request #6792 from tamasvajk/fix/csv-workflow
Let 'ql/lib' folders trigger the CSV workflow
|
2021-10-01 19:44:48 +02:00 |
|
Mathias Vorreiter Pedersen
|
0679142607
|
C++: Accept test changes.
|
2021-10-01 18:27:55 +02:00 |
|
Mathias Vorreiter Pedersen
|
3463c28e24
|
C++: Add return value dereference to 'callOutput'. This will need to be modified once we get return value side effects in the IR.
|
2021-10-01 18:27:46 +02:00 |
|
Marcono1234
|
e3fed55945
|
Java: Add tests for text blocks
|
2021-10-01 18:16:11 +02:00 |
|
Joe Farebrother
|
085701c7db
|
Remove models.csv
|
2021-10-01 17:11:12 +01:00 |
|
Geoffrey White
|
51188aa93f
|
C++: Give the two queries medium precision (for now).
|
2021-10-01 17:04:22 +01:00 |
|
Joe Farebrother
|
5e4498a53a
|
Add more models; fix tests
|
2021-10-01 16:53:53 +01:00 |
|
Geoffrey White
|
a62772c274
|
C++: Add change note.
|
2021-10-01 16:35:12 +01:00 |
|
Marcono1234
|
924b7320bc
|
Java: Add test for NullLiteral
|
2021-10-01 17:27:54 +02:00 |
|
Marcono1234
|
bb6e6f4808
|
Java: Split literals tests
This allows changing individual tests in the future without having to adjust
the expected output of all other tests.
|
2021-10-01 17:27:50 +02:00 |
|
Geoffrey White
|
ada30800c9
|
C++: Exclude results where identity-like functions obscure operations on a variable.
|
2021-10-01 16:16:06 +01:00 |
|
Anders Schack-Mulligen
|
99ba80d492
|
C#: Adjust test output.
|
2021-10-01 16:57:30 +02:00 |
|
Tamas Vajk
|
ebe0988d9a
|
Let 'ql/lib' folders trigger the CSV workflow
|
2021-10-01 16:30:56 +02:00 |
|
Arthur Baars
|
2f462771bb
|
Merge pull request #286 from github/aibaars/xxe
XXE query
|
2021-10-01 16:14:41 +02:00 |
|
Geoffrey White
|
11d7a0b712
|
C++: Exclude results where the address of the variable is taken.
|
2021-10-01 14:39:02 +01:00 |
|
Geoffrey White
|
d41e517757
|
C++: Simplify mayAddNullTerminator.
|
2021-10-01 14:15:05 +01:00 |
|
Geoffrey White
|
ec2e4f432a
|
C++: Add more test cases, inspired by FPs on LGTM with the query.
|
2021-10-01 14:03:41 +01:00 |
|
Geoffrey White
|
74957dcb2e
|
C++: Test spacing.
|
2021-10-01 13:59:34 +01:00 |
|
Anders Schack-Mulligen
|
6359c44622
|
Java: Autoformat.
|
2021-10-01 14:05:47 +02:00 |
|
yoff
|
1ce9426adf
|
Merge pull request #6761 from RasmusWL/cryptodome-sha3
Python/JS: Recognize SHA-3 hash functions
|
2021-10-01 13:33:36 +02:00 |
|
Anders Schack-Mulligen
|
98f68cb053
|
Dataflow: Sync.
|
2021-10-01 13:11:43 +02:00 |
|
Anders Schack-Mulligen
|
490df2027b
|
Dataflow: Add language-specific predicate forceHighPrecision().
|
2021-10-01 13:11:14 +02:00 |
|
Anders Schack-Mulligen
|
d4f1a9602f
|
Dataflow: Force high precision of certain Contents.
|
2021-10-01 13:03:50 +02:00 |
|
Anders Schack-Mulligen
|
eb26b4a04b
|
Merge pull request #6755 from alexet/alexet/cache-params-string
Java: Fix more performance issues with future versions of codeql.
|
2021-10-01 12:54:53 +02:00 |
|
Arthur Baars
|
5a454bb9f2
|
Add comment
|
2021-10-01 12:13:19 +02:00 |
|
Asger Feldthaus
|
c8e7df7900
|
JS: Add test case
|
2021-10-01 12:02:40 +02:00 |
|
Asger Feldthaus
|
600e5bad0d
|
JS: Exclude methods declared private/protected
|
2021-10-01 11:46:32 +02:00 |
|
Asger Feldthaus
|
af1b04de9c
|
JS: Restrict what property names that are considered public exports
|
2021-10-01 11:42:03 +02:00 |
|
Arthur Baars
|
c78d02d00d
|
Fix module of Parser::Options
|
2021-10-01 11:18:03 +02:00 |
|
Arthur Baars
|
b06bb7a789
|
Improve test cases
Set NONET (2048) by default.
|
2021-10-01 11:16:56 +02:00 |
|
Erik Krogh Kristensen
|
5a1eb1995c
|
add change note
|
2021-10-01 11:13:41 +02:00 |
|
Mathias Vorreiter Pedersen
|
a3cf721b9e
|
Merge pull request #6713 from geoffw0/cwe139
C++: New query for 'Cleartext transmission of sensitive information'
|
2021-10-01 11:10:36 +02:00 |
|
Tom Hvitved
|
08225181c8
|
Introduce Expr::getValueText
|
2021-10-01 11:03:46 +02:00 |
|
Geoffrey White
|
679b0f9b73
|
C++: Autoformat.
|
2021-10-01 09:40:16 +01:00 |
|
Rasmus Lerchedahl Petersen
|
175a06fe73
|
Python: Fix compile error due to predicate rename
|
2021-10-01 10:33:42 +02:00 |
|
Anders Schack-Mulligen
|
799e099d1d
|
Merge pull request #6784 from github/workflow/coverage/update
Update CSV framework coverage reports
|
2021-10-01 10:05:34 +02:00 |
|
Erik Krogh Kristensen
|
694016dcbe
|
add missing qldoc
|
2021-10-01 09:01:57 +02:00 |
|
Erik Krogh Kristensen
|
6a9277b5ce
|
recognize string sanitizers for ldap-injection
|
2021-10-01 09:01:29 +02:00 |
|
Erik Krogh Kristensen
|
51b56a9e28
|
add cwe 090 (ldap injection) and cwe 943 (Improper Neutralization of Special Elements in Data Query Logic) to SqlInjection.ql
|
2021-10-01 09:01:29 +02:00 |
|
Erik Krogh Kristensen
|
2062afc868
|
add calls to parseDN as sinks for ldap-injection
|
2021-10-01 09:01:28 +02:00 |
|
Erik Krogh Kristensen
|
d4de5e3248
|
refactoring and renamings in the ldap model
|
2021-10-01 09:01:14 +02:00 |
|
Erik Krogh Kristensen
|
bcf4626fd0
|
remove ldap examples from experimental folder
|
2021-10-01 09:00:10 +02:00 |
|
Erik Krogh Kristensen
|
c55b7bcd85
|
model ldap filters as taint steps
|
2021-10-01 09:00:10 +02:00 |
|
Erik Krogh Kristensen
|
9b5ff66b68
|
naively port tests from ldap examples
|
2021-10-01 09:00:10 +02:00 |
|
Erik Krogh Kristensen
|
2b286a856c
|
naively move ldap into the SQL injection query
|
2021-10-01 09:00:10 +02:00 |
|
Erik Krogh Kristensen
|
94e2676c0f
|
naive conversion of ldapjs model to API node
|
2021-10-01 09:00:10 +02:00 |
|
github-actions[bot]
|
3d61c81456
|
Add changed framework coverage reports
|
2021-10-01 00:09:22 +00:00 |
|
Rasmus Wriedt Larsen
|
2d5c6e2723
|
Python: FastAPI: Add taint test
|
2021-09-30 19:14:15 +02:00 |
|