Mathias Vorreiter Pedersen
|
d05dbb285c
|
Merge pull request #7841 from jketema/structured-bindings-fix
C++: Update C++ variable hiding test
|
2022-02-10 11:29:38 +00:00 |
|
Geoffrey White
|
b0c2a144cc
|
C++: Remove no longer relevant tests.
|
2022-02-10 11:11:31 +00:00 |
|
Geoffrey White
|
20ad92a82e
|
C++: Filter noisiest sources.
|
2022-02-10 11:11:30 +00:00 |
|
Geoffrey White
|
7b5b2fdcd1
|
C++: Modernize cpp/system-data-exposure as a path-problem using IR taint, RemoteFlowSinkFunction.
|
2022-02-10 11:11:26 +00:00 |
|
Geoffrey White
|
5490809bcf
|
C++: Expand tests.
|
2022-02-10 10:43:21 +00:00 |
|
Erik Krogh Kristensen
|
d55920ad27
|
add model for the snapdragon library
|
2022-02-10 11:32:59 +01:00 |
|
Jeroen Ketema
|
46821fe136
|
Update C++ variable hiding test
Structured bindings are now handled better, so the false negative
related to structured bindings is now a true positive.
|
2022-02-10 10:58:32 +01:00 |
|
Tom Hvitved
|
58d90c7f8d
|
Python: More points-to performance improvements
|
2022-02-10 10:29:30 +01:00 |
|
Tom Hvitved
|
7fd8d6dd30
|
Address review comments
|
2022-02-10 10:29:30 +01:00 |
|
Tom Hvitved
|
2de892bfd8
|
Python: Points-to performance improvements
|
2022-02-10 10:29:30 +01:00 |
|
Erik Krogh Kristensen
|
12d31d750a
|
convert more type-trackers to API-graphs
|
2022-02-10 09:54:52 +01:00 |
|
Stephan Brandauer
|
a73cdf3527
|
Merge pull request #7911 from kaeluka/javascript/add-getFlowLabel-to-PathNode
JS: add a getFlowLabel method to the PathNode class
|
2022-02-10 09:10:08 +01:00 |
|
Jonathan Leitschuh
|
bafcce17d4
|
Apply suggestions from code review
Co-authored-by: Chris Smowton <smowton@github.com>
|
2022-02-09 22:14:17 -05:00 |
|
Harry Maclean
|
d966ca8466
|
Ruby: recognise additional form for OpenURI
|
2022-02-10 15:42:15 +13:00 |
|
luchua-bc
|
ce03aeb4d9
|
Fixed an issue related to normalized path
|
2022-02-09 23:19:40 +00:00 |
|
Rasmus Wriedt Larsen
|
94f9656e8e
|
Python: Solve deprecation warnings for old experimental queries
|
2022-02-10 00:09:43 +01:00 |
|
Harry Maclean
|
f30222256f
|
Merge pull request #7061 from github/hmac/actiondispatch
Ruby: Rails route resolution
|
2022-02-10 09:46:36 +13:00 |
|
Ethan Palm
|
2f7f9d9032
|
Move explanation of example above sample code
|
2022-02-09 10:45:24 -08:00 |
|
Jonathan Leitschuh
|
ded8d64301
|
Remove CAPC and add CWE-93
|
2022-02-09 12:31:53 -05:00 |
|
Jonathan Leitschuh
|
03fdee3767
|
Cleanup Netty Response Splitting Query
|
2022-02-09 12:28:11 -05:00 |
|
Jonathan Leitschuh
|
8ffe878722
|
Apply suggestions from code review
Co-authored-by: Matt Pollard <mattpollard@users.noreply.github.com>
|
2022-02-09 12:28:11 -05:00 |
|
Jonathan Leitschuh
|
c732cb7759
|
Add HTTP Request Splitting to Netty Query
|
2022-02-09 12:28:10 -05:00 |
|
Stephan Brandauer
|
3e88d46e0f
|
add a getFlowLabel method to the PathNode class
|
2022-02-09 17:28:25 +01:00 |
|
Jonathan Leitschuh
|
49a73673b6
|
Fix FP from mkdirs call on exact temp directory
|
2022-02-09 11:04:23 -05:00 |
|
Tamás Vajk
|
6483a92587
|
Merge pull request #7865 from github/post-release-prep/codeql-cli-2.8.0
Post-release preparation for codeql-cli-2.8.0
|
2022-02-09 16:42:38 +01:00 |
|
Jonathan Leitschuh
|
787e3dac31
|
Update java/ql/src/Security/CWE/CWE-200/TempDirLocalInformationDisclosure.ql
Co-authored-by: Chris Smowton <smowton@github.com>
|
2022-02-09 10:07:56 -05:00 |
|
Tom Hvitved
|
c695388c29
|
Merge pull request #7891 from hvitved/ruby/dataflow/hide-ssa-nodes
Ruby: Hide more SSA nodes from data-flow path explanations
|
2022-02-09 15:56:15 +01:00 |
|
Tom Hvitved
|
0bd8411cb6
|
Ruby: Hide more SSA nodes from data-flow path explanations
|
2022-02-09 15:31:10 +01:00 |
|
Rasmus Lerchedahl Petersen
|
aa010e420b
|
python: update qhelp
|
2022-02-09 15:27:39 +01:00 |
|
Rasmus Lerchedahl Petersen
|
75a2f92ce4
|
pthon: add change note
|
2022-02-09 15:23:36 +01:00 |
|
Mathias Vorreiter Pedersen
|
336c25d929
|
Merge pull request #7913 from RasmusWL/ql-qlpacks
QL: Streamline qlpacks
|
2022-02-09 13:37:19 +00:00 |
|
Rasmus Lerchedahl Petersen
|
313f9f056c
|
python: switch to using concepts
|
2022-02-09 14:36:48 +01:00 |
|
Rasmus Lerchedahl Petersen
|
17aa2898f9
|
python: model (xpathEval from) libxml2
|
2022-02-09 14:25:43 +01:00 |
|
Rasmus Lerchedahl Petersen
|
e8649d8947
|
python: model (etree from) lxml
|
2022-02-09 14:15:17 +01:00 |
|
Rasmus Wriedt Larsen
|
1f50624cf4
|
QL: Streamline qlpacks
So they follow the same format as the other languages.
`git grep codeql-ql` in the ql/ subfolder does not yield any results
now.
|
2022-02-09 14:08:36 +01:00 |
|
Rasmus Wriedt Larsen
|
9d5e8d5bd8
|
Merge pull request #7842 from RasmusWL/consistency-queires
Misc: Streamline `consistency-queries/qlpack.yml`
|
2022-02-09 13:42:18 +01:00 |
|
jorgectf
|
85b5ef36ae
|
XmlInjection -> XmlEntityInjection
|
2022-02-09 13:28:56 +01:00 |
|
Nick Rolfe
|
1eba8277ee
|
Merge pull request #7614 from github/nickrolfe/array_flow_summaries
Ruby: add more Array/Enumerable flow summaries
|
2022-02-09 09:57:59 +00:00 |
|
Harry Maclean
|
f276904fa9
|
Ruby: Add nomagic pragma to helper
|
2022-02-09 22:38:35 +13:00 |
|
Michael Nebel
|
ff369f2a36
|
Merge pull request #7846 from michaelnebel/csharp/deconstruction
C# 10: Tuple deconstruction.
|
2022-02-09 10:08:16 +01:00 |
|
Mathias Vorreiter Pedersen
|
bbbb5268ce
|
Merge pull request #7881 from geoffw0/clrtxtperf
CPP: Fix performance for cpp/cleartext-transmission
|
2022-02-09 09:03:44 +00:00 |
|
Erik Krogh Kristensen
|
5340530cb7
|
use the number guard in existing queries that contained typeof checks
|
2022-02-09 09:51:57 +01:00 |
|
Erik Krogh Kristensen
|
d6721ec574
|
implement a isNaN guard for unsafe-shell-command-construction
|
2022-02-09 09:51:57 +01:00 |
|
Tom Hvitved
|
9440a45015
|
Merge branch 'main' into post-release-prep/codeql-cli-2.8.0
|
2022-02-09 09:40:33 +01:00 |
|
yoff
|
f21ac04285
|
Update python/ql/lib/semmle/python/frameworks/Stdlib.qll
Co-authored-by: Rasmus Wriedt Larsen <rasmuswriedtlarsen@gmail.com>
|
2022-02-09 09:22:31 +01:00 |
|
luchua-bc
|
4609227e76
|
Use data model for request/session attribute operations
|
2022-02-09 03:24:46 +00:00 |
|
jorgectf
|
3ccac4ed8a
|
Update .expected
|
2022-02-08 23:59:36 +01:00 |
|
Jonathan Leitschuh
|
7f46640176
|
Consider calls to setReadable(false, false) then setReadable(true, true) to be safe
|
2022-02-08 17:57:10 -05:00 |
|
jorgectf
|
c6d8b97871
|
Make verifyCall() a private predicate
|
2022-02-08 23:37:17 +01:00 |
|
jorgectf
|
7b51b91d13
|
Improve test
|
2022-02-08 23:33:43 +01:00 |
|