Commit Graph

  • aa964362ef C#: Update rules_dotnet to 0.21.5. Michael Nebel 2025-11-24 12:24:30 +01:00
  • 577a2e1974 C#: Copy the 0.19.2 custom rules_dotnet. Michael Nebel 2025-11-24 13:07:57 +01:00
  • 8c39472d73 Rust: Add change note for reads as taint steps Simon Friis Vindum 2025-12-11 09:09:12 +01:00
  • d5a95a8099 Rust: Strengthen isNotInstantiationOf uses Tom Hvitved 2025-12-10 20:44:27 +01:00
  • f30a3b3712 Rust: Add type inference blowup test Tom Hvitved 2025-12-10 20:19:58 +01:00
  • f1d241f810 Rust: Accept test change. Geoffrey White 2025-12-10 18:09:12 +00:00
  • d9d754c485 Add query to identify redundant environment definitions from context expressions mario-campos/env-alias-query Mario Campos 2025-12-10 11:17:51 -06:00
  • 6ca90a2d62 Rust: Change note. Geoffrey White 2025-12-10 16:23:04 +00:00
  • c160a1f658 Rust: Fix common FPs for rust/unused-variable and rust/unused-value. Geoffrey White 2025-12-10 15:55:28 +00:00
  • 000f2c345e Merge pull request #21001 from aschackmull/guards/generalise-validationwrapper Anders Schack-Mulligen 2025-12-10 15:52:53 +01:00
  • c6d2047827 Rust: Update expected files Simon Friis Vindum 2025-11-28 12:40:00 +01:00
  • d2c7147480 Python: Add new test tausbn/python-add-models-for-zstd-compression Taus 2025-12-10 13:52:13 +00:00
  • 6af9fd816f Python: Make space for new test Taus 2025-12-10 13:20:19 +00:00
  • efbc0934c4 Rust: Do not use types to limit lifting of reads to taint steps Simon Friis Vindum 2025-11-28 11:27:30 +01:00
  • fe37e3d9be Rust: Address PR feedback Simon Friis Vindum 2025-11-28 09:42:35 +01:00
  • 273eb19b88 Rust: Apply suggestions from code review Simon Friis Vindum 2025-11-28 09:24:31 +01:00
  • 5ba4e30c20 Rust: Exclude range start and end from field taint steps Simon Friis Vindum 2025-11-27 09:24:18 +01:00
  • 647bed9e2f Rust: Add extensible predicate to exclude fields and block fieldless enum types Simon Friis Vindum 2025-11-26 13:09:41 +01:00
  • 6fcd8d194a Rust: Refactor flow summary implementation Simon Friis Vindum 2025-11-26 13:02:17 +01:00
  • 047ea10a9a Rust: Update tests and expected files Simon Friis Vindum 2025-11-21 12:28:04 +01:00
  • 0f97e7e29d Rust: Remov unneeded model Simon Friis Vindum 2025-11-21 12:44:59 +01:00
  • 8a0e5b5675 Rust: Lift content reads as taint steps Simon Friis Vindum 2025-11-20 17:12:25 +01:00
  • cd721b85e9 Merge pull request #20941 from paldepind/rust/invalid-pointer-barriers Simon Friis Vindum 2025-12-10 14:22:05 +01:00
  • eaa96864f7 Java: Extend test to cover assertion-like barrier guards. Anders Schack-Mulligen 2025-12-10 12:20:56 +01:00
  • 9cd2247b91 Java: expose support for more general BarrierGuards. Anders Schack-Mulligen 2025-12-10 11:21:01 +01:00
  • 09058e48aa Guards: Rename -WithState to Parameterized-. Anders Schack-Mulligen 2025-12-09 16:30:07 +01:00
  • ebb989962c Guards: Generalise ValidationWrapper to support GuardValue-based BarrierGuards. Anders Schack-Mulligen 2025-12-09 16:17:46 +01:00
  • c5a44cf8ff Rust: Accept changes to expected files Simon Friis Vindum 2025-12-10 09:53:07 +01:00
  • 506a1ea0b8 Rust: Add test case for rust/access-after-lifetime-ended involving an invalidated reference. Geoffrey White 2025-12-09 14:32:12 +00:00
  • ade7815125 Rust: Add change note Simon Friis Vindum 2025-12-05 14:35:26 +01:00
  • 7d1acbcb87 Rust: Restrict the scope of DereferenceSink to dereferences of raw pointers Simon Friis Vindum 2025-12-05 11:19:06 +01:00
  • 4a1abc7beb Merge pull request #21007 from hvitved/rust/update-expected Simon Friis Vindum 2025-12-10 11:19:37 +01:00
  • fa02842d30 Rust: Accept consistency check changes. Geoffrey White 2025-12-10 10:16:22 +00:00
  • 30b903604d Rust: Update expected test output Tom Hvitved 2025-12-10 11:02:04 +01:00
  • 3cabcfef75 Swift: Skip -scan-dependencies compiler calls Jeroen Ketema 2025-12-10 10:11:41 +01:00
  • e9aa6ddf53 Swift: Strip more unsupported arguments Jeroen Ketema 2025-12-10 10:08:21 +01:00
  • 819a12216e Merge branch 'main' into copilot/add-ecb-cbc-test-cases Geoffrey White 2025-12-10 08:56:20 +00:00
  • e6e05012c8 Python: Add change note Taus 2025-12-09 22:55:40 +00:00
  • ad68a5e4e9 Python: Add modelling for zstd.compression Taus 2025-12-09 22:50:51 +00:00
  • 545241aa65 Python: Add change note tausbn/python-support-relaxed-exception-groups Taus 2025-12-09 17:09:40 +00:00
  • fe18e0e414 Merge pull request #20997 from paldepind/rust/fix-expected Tom Hvitved 2025-12-09 14:25:36 +01:00
  • a5f513f178 Merge pull request #20954 from hvitved/rust/stats-more-calls Tom Hvitved 2025-12-09 14:14:07 +01:00
  • 53ad3282c3 Rust: Accept changes to expected files Simon Friis Vindum 2025-12-09 13:47:53 +01:00
  • cf19586516 Merge pull request #20993 from github/dependabot/go_modules/go/extractor/extractor-dependencies-955632e86c Owen Mansel-Chan 2025-12-09 09:36:16 +00:00
  • 139dc0acaf Merge pull request #20922 from aschackmull/csharp/object-initializer Anders Schack-Mulligen 2025-12-09 10:35:02 +01:00
  • 5c6d83ed65 Merge pull request #20877 from joefarebrother/python-tornado-websocket yoff 2025-12-09 10:08:59 +01:00
  • 8ecae77887 Merge pull request #20991 from github/dependabot/nuget/csharp/ql/integration-tests/posix/standalone_dependencies_no_framework/nuget-335537b6a2 Michael Nebel 2025-12-09 10:01:15 +01:00
  • e054741061 Update expected test output Tom Hvitved 2025-12-09 09:13:26 +01:00
  • 31b184a404 Rust: Exclude deref expressions on raw pointers from call resolution stats Tom Hvitved 2025-12-09 08:54:51 +01:00
  • 9eb1eb8f0d Bump the extractor-dependencies group in /go/extractor with 2 updates dependabot[bot] 2025-12-09 03:07:27 +00:00
  • e7147244e8 Merge pull request #20992 from myvyang/main Owen Mansel-Chan 2025-12-09 01:22:55 +00:00
  • d15342db1f Fix table padding Owen Mansel-Chan 2025-12-09 01:12:53 +00:00
  • 134312173f MethodAccess has been deprecated, Change MethodAccess to MethodCall in query example. i 2025-12-09 08:41:01 +08:00
  • c8992fc834 Bump the nuget group with 1 update dependabot[bot] 2025-12-09 00:33:13 +00:00
  • 8286483b53 Python: Add parser test Taus 2025-12-08 17:12:21 +00:00
  • 685f672ea1 Python: Regenerate parser files Taus 2025-12-08 17:11:30 +00:00
  • 6ba65b0dd2 Python: Add support for PEP-758 exception syntax Taus 2025-12-08 17:09:40 +00:00
  • 2854330759 Post-release preparation for codeql-cli-2.23.8 github-actions[bot] 2025-12-08 15:49:10 +00:00
  • 28b6aa8616 Merge pull request #20988 from github/release-prep/2.23.8 codeql-cli/v2.23.8 codeql-cli/latest lgtm.com codeql-cli-2.23.8 Paolo Tranquilli 2025-12-08 15:45:10 +01:00
  • 66c51e979e Release preparation for version 2.23.8 github-actions[bot] 2025-12-08 14:38:23 +00:00
  • b5f705a4f1 Merge pull request #20985 from asgerf/js/overlay-local-optional Paolo Tranquilli 2025-12-08 15:27:23 +01:00
  • 359a28e409 Merge pull request #20984 from github/rc/3.20 Chris Smowton 2025-12-08 14:24:58 +00:00
  • 0280771c51 Merge pull request #20953 from hvitved/rust/data-flow-call-models Tom Hvitved 2025-12-08 15:22:02 +01:00
  • 57ce2ee749 Address review comments Tom Hvitved 2025-12-08 13:27:36 +01:00
  • 4d1200fd13 Revert changes in synced files Asger F 2025-12-08 13:26:19 +01:00
  • ef991e5ba5 Merge pull request #20983 from smowton/smowton/feature/csharp-csrf-aspnetcore Chris Smowton 2025-12-08 12:14:48 +00:00
  • 294089fe35 JS: Use question-mark variant in all overlay annotations Asger F 2025-12-08 13:10:29 +01:00
  • 877669d1f0 Merge pull request #20981 from github/idrissrio/java/java-maven-sap Idriss Riouak 2025-12-08 12:55:50 +01:00
  • 79718b6dcb Change note Chris Smowton 2025-12-08 11:54:02 +00:00
  • 5bb31afc83 C# CSRF query: add support for ASP.NET Core Chris Smowton 2025-12-08 11:51:01 +00:00
  • a0e7afde8e Java: Add change note for Maven compiler flags idrissrio 2025-12-08 12:07:01 +01:00
  • cd6429a39e Merge pull request #20969 from paldepind/rust/dispath-default-trait Simon Friis Vindum 2025-12-08 10:45:55 +01:00
  • bfa37b8488 Fix typo Tom Hvitved 2025-12-08 10:17:47 +01:00
  • 24852c6664 Merge pull request #20966 from geoffw0/lifetimetest Geoffrey White 2025-12-08 09:03:51 +00:00
  • 10c01832b0 Merge pull request #20964 from michaelnebel/csharp/nugetversionsorting Michael Nebel 2025-12-08 09:35:53 +01:00
  • 3230df02d9 Merge pull request #20975 from github/oscarsj/merge-back-rc-3.20 Óscar San José 2025-12-05 21:16:18 +01:00
  • bc6133de5c Merge branch 'main' of https://github.com/github/codeql into oscarsj/merge-back-rc-3.20 Óscar San José 2025-12-05 19:31:47 +01:00
  • 6ebaff3fdd Python: Fix broken queries tausbn/python-add-ast-overlay-annotations Taus 2025-12-05 13:48:28 +00:00
  • 9a95acadb5 Merge pull request #20963 from hvitved/rust/call-refactor-follow-up Tom Hvitved 2025-12-05 14:38:47 +01:00
  • 2acb02bf67 Merge pull request #20971 from github/redsun82/ripunzip Paolo Tranquilli 2025-12-05 14:32:55 +01:00
  • 09e1f8d5ad Python: Add overlay annotations to AST classes Taus 2025-12-05 13:23:11 +00:00
  • 1b519384d7 Merge pull request #20739 from github/tausbn/python-remove-top-level-points-to-imports Taus 2025-12-05 14:24:41 +01:00
  • 108db75124 Update rust/ql/lib/codeql/rust/security/AccessAfterLifetimeExtensions.qll Geoffrey White 2025-12-05 13:19:38 +00:00
  • f200dba7dd Rust: Add change note Simon Friis Vindum 2025-12-05 14:12:22 +01:00
  • fa4b212020 Rust: Fix grammar Simon Friis Vindum 2025-12-05 14:03:29 +01:00
  • 90aeccab07 Ripunzip: update to 2.0.4 Paolo Tranquilli 2025-12-05 13:55:33 +01:00
  • 86962c6055 Merge pull request #20970 from github/smowton/admin/document-missing-actions-permissions-shortcomings Chris Smowton 2025-12-05 12:43:49 +00:00
  • 02caa098bc Actions: note imprecision of MissingActionsPermissions.ql Chris Smowton 2025-12-05 12:36:07 +00:00
  • 5888ed30bd Rust: Do not dispatch to all implementations when trait target is accurate Simon Friis Vindum 2025-12-05 10:17:43 +01:00
  • 5addb53e0f Merge pull request #20946 from github/post-release-prep/codeql-cli-2.23.7 Óscar San José 2025-12-05 12:51:51 +01:00
  • 12a6dcc4ff Rust: Remove some predicates Tom Hvitved 2025-12-04 12:55:43 +01:00
  • 28e9420476 C#: Fix lambda flow. Anders Schack-Mulligen 2025-12-05 10:58:01 +01:00
  • 795bfdf02d Merge pull request #20962 from github/redsun82/dependabot Paolo Tranquilli 2025-12-05 10:51:29 +01:00
  • 59ce721f7d Rust: Add global data flow example Simon Friis Vindum 2025-12-05 09:26:18 +01:00
  • 2e8db582f4 Kotlin: Fix bazel format and address copilot review comments andersfugmann/kotlin_2.3.0-beta2 Anders Fugmann 2025-12-05 09:21:39 +01:00
  • 5a5679bd51 Rust: Taint flow through operations using MaD Tom Hvitved 2025-12-02 15:29:37 +01:00
  • 41916640c3 Rust: Taint flow tests for operations Tom Hvitved 2025-12-02 15:28:25 +01:00
  • 294c489fd8 Rust: Handle x[y] expressions as *.index(y) calls in data flow Tom Hvitved 2025-12-01 14:24:06 +01:00
  • e72c8acb6c Rust: Add data flow tests for collections Tom Hvitved 2025-12-01 14:06:59 +01:00
  • 09461e9cb6 Merge pull request #20967 from hvitved/rust/call-refactor-fix Tom Hvitved 2025-12-05 09:16:18 +01:00