Jonathan Leitschuh
|
df716cbaa0
|
Revert changes to MethodAccessSystemGetProperty
|
2022-02-04 17:10:25 -05:00 |
|
Jonathan Leitschuh
|
66831989b7
|
Add QLdoc to TempDirUtils
|
2022-02-04 17:10:25 -05:00 |
|
Jonathan Leitschuh
|
7e55c92eb4
|
Apply suggestions from code review
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2022-02-04 17:10:25 -05:00 |
|
Jonathan Leitschuh
|
c19f52cd04
|
Add release notes for "Temporary Directory Local information disclosure"
|
2022-02-04 17:10:25 -05:00 |
|
Jonathan Leitschuh
|
f6067d28f9
|
Fix file names and formatting from PR feedback
|
2022-02-04 17:10:25 -05:00 |
|
Jonathan Leitschuh
|
41b5011b81
|
Apply suggestions from code review
Co-authored-by: Felicity Chapman <felicitymay@github.com>
|
2022-02-04 17:10:25 -05:00 |
|
Jonathan Leitschuh
|
7929faedc0
|
Apply suggestions from code review
Co-authored-by: Felicity Chapman <felicitymay@github.com>
|
2022-02-04 17:10:25 -05:00 |
|
Jonathan Leitschuh
|
f910fd4719
|
Remove path flow tracking in 'TempDirLocalInformationDisclosureFromMethodCall'
|
2022-02-04 17:10:25 -05:00 |
|
Jonathan Leitschuh
|
e4c017e888
|
Apply suggestions from code review
Co-authored-by: Arthur Baars <aibaars@github.com>
|
2022-02-04 17:10:24 -05:00 |
|
Jonathan Leitschuh
|
13fed0e9b6
|
Temp Dir Info Disclosure: Final pass and add documentation
|
2022-02-04 17:10:24 -05:00 |
|
Jonathan Leitschuh
|
bc12e994b0
|
Add java.nio.file.Files API checks
|
2022-02-04 17:10:24 -05:00 |
|
Jonathan Leitschuh
|
ecad7534ae
|
Add mkdirs check
|
2022-02-04 17:10:24 -05:00 |
|
Jonathan Leitschuh
|
cf0ed81575
|
Add TempDir taint tracking for Files.write
|
2022-02-04 17:10:24 -05:00 |
|
Jonathan Leitschuh
|
3a15678b1e
|
Java: CWE-200: Temp directory local information disclosure vulnerability
|
2022-02-04 17:10:23 -05:00 |
|
Erik Krogh Kristensen
|
ab2d3a7ca0
|
Merge pull request #7828 from Naman-ntc/main
JS: Adding model for `.get` function of `Map` in Unvalidated Dynamic Method Call
|
2022-02-04 20:19:02 +01:00 |
|
Erik Krogh Kristensen
|
f00d723c49
|
Merge pull request #7843 from erik-krogh/CVE-2021-23484
JS: add file sources from `jszip` to `js/zip-slip`
|
2022-02-04 20:17:43 +01:00 |
|
BACK Yonah
|
21fdc53d62
|
C/C++: Using UnspecifiedType instead of Type
|
2022-02-04 19:12:15 +01:00 |
|
Nick Rolfe
|
9744cf2457
|
Ruby: apply suggested simplification from review
|
2022-02-04 17:14:47 +00:00 |
|
Nick Rolfe
|
aaff3226c9
|
Ruby: prefer ...isInt(x) over x = ...getInt()
|
2022-02-04 17:10:22 +00:00 |
|
BACK Yonah
|
b2ca25abef
|
Merge branch 'main' of https://github.com/github/codeql
|
2022-02-04 18:09:19 +01:00 |
|
BACK Yonah
|
f4a1d1d5e6
|
C/C++: Useless Test Fully converted verification
|
2022-02-04 18:05:03 +01:00 |
|
Nick Rolfe
|
45962f1cad
|
Ruby: make this unique for each method
Even when summaries are shared in a single class.
|
2022-02-04 17:03:55 +00:00 |
|
BACK Yonah
|
34320cb57b
|
C/C++: Useless Test Fully converted verification
|
2022-02-04 18:03:29 +01:00 |
|
Ian Wright
|
6c3daf49f9
|
Merge pull request #7785 from github/z80coder/impose-length-restriction
Restrict AST nodes according to string length
|
2022-02-04 16:35:04 +00:00 |
|
Nick Rolfe
|
7a9ddc28bf
|
Ruby: address some more feedback on array flow summaries
|
2022-02-04 16:33:27 +00:00 |
|
Henry Mercer
|
bb1e89d261
|
Merge pull request #7848 from github/henrymercer/js-ml-powered-codeowners
JS: Add codeowners for ML-powered queries
|
2022-02-04 16:08:56 +00:00 |
|
Michael Nebel
|
6ee30843bb
|
C#: Add lambda attributes test cases.
|
2022-02-04 16:54:49 +01:00 |
|
Henry Mercer
|
22ef35e13a
|
JS: Add codeowners for ML-powered queries
Create a new reviewers team @github/codeql-ml-powered-queries-reviewers
for reviewing ML-powered queries and the associated CodeQL libraries.
|
2022-02-04 15:49:44 +00:00 |
|
Ian Wright
|
be5e8dae05
|
Update javascript/ql/experimental/adaptivethreatmodeling/lib/experimental/adaptivethreatmodeling/FunctionBodyFeatures.qll
Co-authored-by: Henry Mercer <henrymercer@github.com>
|
2022-02-04 15:41:50 +00:00 |
|
Michael Nebel
|
7b3ba3cb96
|
C#: Modify database schema to allow lambda expression to be attributable and extract the lambda expression attributes.
|
2022-02-04 16:34:58 +01:00 |
|
Michael Nebel
|
f412d49ba4
|
C#: Add some examples lambdas with different kind of attributes and update existing testcases.
|
2022-02-04 16:34:58 +01:00 |
|
Michael Nebel
|
bb3f9cea3a
|
C#: Update test cases(s) expected output.
|
2022-02-04 16:34:58 +01:00 |
|
Michael Nebel
|
7520948ec4
|
C#: Add test case for finding lambdas with explicit return types.
|
2022-02-04 16:34:58 +01:00 |
|
Michael Nebel
|
83a5ef4961
|
C#: Examples of lambda expressions with explicit return types.
|
2022-02-04 16:34:58 +01:00 |
|
Michael Nebel
|
25019dbaa0
|
C#: Add support QL library support for lambda explicit return types.
|
2022-02-04 16:34:58 +01:00 |
|
Michael Nebel
|
eb8c226749
|
C#: Add support for explicit return types in the extractor.
|
2022-02-04 16:34:58 +01:00 |
|
Michael Nebel
|
ae62704d3a
|
C#: Add table for explicit return type in lambda expressions.
|
2022-02-04 16:34:57 +01:00 |
|
Michael Nebel
|
ccb727e3ca
|
C#: Test cases that shows that lambdas can be naturally (implicitly) typed and that the type is indistinguishable from the equivalent explicitly typed declaration.
|
2022-02-04 16:34:57 +01:00 |
|
Michael Nebel
|
a67033034a
|
C#: Example of naturally typed lambda.
|
2022-02-04 16:34:57 +01:00 |
|
jorgectf
|
43fde3561f
|
Merge branch 'jorgectf/python/deserialization' of https://github.com/jorgectf/codeql into jorgectf/python/deserialization
|
2022-02-04 16:32:11 +01:00 |
|
Jorge
|
d96eb01b9c
|
Merge branch 'github:main' into jorgectf/python/deserialization
|
2022-02-04 16:32:01 +01:00 |
|
Ian Wright
|
e57a0e0e2f
|
Update javascript/ql/experimental/adaptivethreatmodeling/lib/experimental/adaptivethreatmodeling/FunctionBodyFeatures.qll
Co-authored-by: Henry Mercer <henrymercer@github.com>
|
2022-02-04 15:21:56 +00:00 |
|
Ian Wright
|
b38335a6c2
|
add QL comment; inline a predicate; restore a comment
|
2022-02-04 15:21:09 +00:00 |
|
Nick Rolfe
|
ed00f2b0d2
|
Ruby: address some feedback on array flow summaries
|
2022-02-04 13:40:39 +00:00 |
|
Erik Krogh Kristensen
|
edcb3ba902
|
add file sources from jszip to js/zip-slip
|
2022-02-04 14:39:49 +01:00 |
|
Tom Hvitved
|
693aa69abd
|
Update csharp/ql/consistency-queries/qlpack.yml
|
2022-02-04 14:38:25 +01:00 |
|
yoff
|
182c62f5c3
|
Merge pull request #7838 from tausbn/python-fix-charset-performance-problem
Python: Fix performance issue in `charSet`
|
2022-02-04 14:18:13 +01:00 |
|
Michael Nebel
|
567768134f
|
Merge pull request #7792 from michaelnebel/csharp/attributes
C#: Attribute kind and return value attributes.
|
2022-02-04 14:10:51 +01:00 |
|
Taus
|
67be20f368
|
Python: Remove implied inequalities
Also gets rid of `inner_end`, since we're already doing `end - 1 = ...`
in the other fix (and so this is more consistent).
|
2022-02-04 12:46:06 +00:00 |
|
Benjamin Muskalla
|
eee03ebe3b
|
Merge pull request #7767 from bmuskalla/regenerateModelScript
Java: Regenerate framework models automatically
|
2022-02-04 13:29:46 +01:00 |
|