Commit Graph

  • 57bca5ca9b Rust: Include more calls in DB quality metrics Tom Hvitved 2025-12-02 09:22:58 +01:00
  • 1a19df2044 Merge pull request #20950 from paldepind/rust/ti-raw-pointer Simon Friis Vindum 2025-12-05 09:06:13 +01:00
  • 6d301f27d0 Merge pull request #20937 from owen-mc/actions/fix/code-injection-privileged-context Owen Mansel-Chan 2025-12-05 07:54:13 +00:00
  • d70c596c86 Merge pull request #20914 from joefarebrother/python-socketio Joe Farebrother 2025-12-04 23:14:58 +00:00
  • a35fba1e36 Python: Add change note tausbn/python-add-support-for-template-string-literals Taus 2025-12-04 22:14:15 +00:00
  • 98279f7c75 Python: Add stats Taus 2025-12-04 16:01:22 +00:00
  • 44bf762817 Python: Add up-/downgrade scripts for template literals Taus 2025-12-04 15:09:21 +00:00
  • be1d756de4 Rust: Call refactor follow-up fixes Tom Hvitved 2025-12-04 21:12:19 +01:00
  • 4109848927 Rust: Clean up following merge. Geoffrey White 2025-12-04 17:55:34 +00:00
  • b7402fef09 Merge remote-tracking branch 'upstream/main' into lifetimetest Geoffrey White 2025-12-04 17:33:39 +00:00
  • 3cdbef71f1 Rust: Change note. Geoffrey White 2025-12-04 17:25:34 +00:00
  • 32e9fdfe19 Rust: Fix the false positives. Geoffrey White 2025-12-04 17:12:38 +00:00
  • 4a16de2bc8 Pull out logic into separate predicate Owen Mansel-Chan 2025-12-03 12:59:35 +00:00
  • fb841ea591 Make predicates containing query logic more self-contained Owen Mansel-Chan 2025-12-03 11:27:35 +00:00
  • 8bac1dec83 Add change note Owen Mansel-Chan 2025-11-29 01:06:00 +00:00
  • f6bdb3a126 Fix filtering of code injection alerts between medium and critical Owen Mansel-Chan 2025-11-28 23:17:35 +00:00
  • e2acd1b668 Add test with push and workflow_dispatch triggers Owen Mansel-Chan 2025-11-28 23:15:36 +00:00
  • f709d02464 Python: Bump extractor version Taus 2025-12-04 13:48:32 +00:00
  • 89f66d77e5 Python: Add AST node wrappers Taus 2025-12-04 13:46:53 +00:00
  • 68733a83e9 Python: Regenerate AST and dbscheme files Taus 2025-10-28 22:06:15 +00:00
  • 48cd54165a Python: Support template strings in rest of extractor Taus 2025-10-28 22:05:53 +00:00
  • 5928d0ff12 Python: Regenerate parser files Taus 2025-10-28 21:59:32 +00:00
  • 287e18d02c Python: Add parser support for template strings Taus 2025-10-28 21:59:18 +00:00
  • ecc8a91f7b Kotlin: Update compiler plugin for Kotlin 2.3.0-Beta2 Anders Fugmann 2025-12-04 17:05:58 +01:00
  • 8b89e15dfa Merge pull request #20863 from hvitved/rust/call-refactor Tom Hvitved 2025-12-04 17:02:17 +01:00
  • 27ddc813af Rust: Cleanup of raw pointer types based in PR feedback Simon Friis Vindum 2025-12-04 16:22:54 +01:00
  • 5c8ab1f6d1 Merge pull request #20956 from owen-mc/java/improve-regex-sanitizer Owen Mansel-Chan 2025-12-04 15:32:12 +00:00
  • 8594c7a29a Rust: Add test for rust/access-after-lifetime-ended FP involving generic calls. Geoffrey White 2025-12-04 15:21:18 +00:00
  • 144510c23d Kotlin: Add support for Kotlin 2.3.0-Beta2 Anders Fugmann 2025-12-04 16:14:13 +01:00
  • 90dd3b9449 Kotlin: Silence compilation warnings Anders Fugmann 2025-12-04 16:12:24 +01:00
  • c7d65ef349 Kotlin: Remove resource_strip_prefix for kotlin extraction Anders Fugmann 2025-12-04 16:01:50 +01:00
  • 3c81d5a09c Kotlin: Update kotlin_rules to 2.2.0 and remove support for Kotlin 1.6 and 1.7 Anders Fugmann 2025-12-04 15:56:48 +01:00
  • 5a33f9fcd8 C#: Update integration test expected output. Michael Nebel 2025-12-04 15:58:02 +01:00
  • 4112cfc8f1 C#: Add change note. Michael Nebel 2025-12-04 15:42:18 +01:00
  • a3e545ddd5 C#: Use NuGetVersion instead of homemade version implementation. Michael Nebel 2025-12-04 14:26:27 +01:00
  • 1b84f70d1c C#: Use NuGet version sorting instead of lexicographic directory name sorting for finding newest package version. Michael Nebel 2025-11-25 13:48:03 +01:00
  • 4274af4f73 C#: Set AllowMissingPrunePackageData=true to true when purposely using non-existing framework targets. Michael Nebel 2025-11-25 13:44:29 +01:00
  • e4ee7c95c5 C#: Address review comments. Anders Schack-Mulligen 2025-12-04 14:36:40 +01:00
  • cdd8aa49e1 Merge pull request #20933 from michaelnebel/csharp/runtraceraftercompilation Michael Nebel 2025-12-04 13:41:38 +01:00
  • a20c8cfd52 Add post-update nodes for implicit field read nodes Owen Mansel-Chan 2025-11-26 10:18:02 +00:00
  • dcfa721037 (Refactor) Make lookThroughImplicitFieldRead public Owen Mansel-Chan 2025-11-26 10:17:49 +00:00
  • 9bf20702c6 Remove identity steps Owen Mansel-Chan 2025-11-26 10:15:06 +00:00
  • bc6d38ebb4 Address review comments Tom Hvitved 2025-12-03 21:08:42 +01:00
  • 607ad1f886 Merge pull request #20961 from aschackmull/dataflow/flowfrom Anders Schack-Mulligen 2025-12-04 10:09:29 +01:00
  • e74031bee4 Merge pull request #20936 from michaelnebel/csharp/nocrashdotnetinfo Michael Nebel 2025-12-04 09:13:12 +01:00
  • 38a572dfa0 Rust: Run codegen Tom Hvitved 2025-12-03 20:47:05 +01:00
  • a707527022 Address review comments in annotations.py Tom Hvitved 2025-12-03 20:46:30 +01:00
  • 2665d8395a Merge pull request #20939 from geoffw0/saltmodel Geoffrey White 2025-12-03 18:01:48 +00:00
  • ca9d327280 Merge pull request #20915 from hvitved/content-flow-ap-limit Tom Hvitved 2025-12-03 15:54:57 +01:00
  • a903420122 C#: Add change note. Michael Nebel 2025-12-03 14:03:00 +01:00
  • 0d08f24a2d C#: Invoke the extractor after the compiler to ensure that source generators have been executed. Michael Nebel 2025-11-27 11:23:51 +01:00
  • 7fd4755e93 Merge pull request #20919 from yoff/python/header-splitting-experiments yoff 2025-12-03 15:48:54 +01:00
  • 3ba256a72a C#/Java: Go back to access path limit 2 Tom Hvitved 2025-12-03 15:05:02 +01:00
  • 599d342b33 Dependabot: add bazel Paolo Tranquilli 2025-12-03 14:52:02 +01:00
  • 78e1879c9e Use more flowTo. Anders Schack-Mulligen 2025-12-03 14:12:08 +01:00
  • dc6d3fe7ba Use flowFrom. Anders Schack-Mulligen 2025-12-03 14:04:18 +01:00
  • 4191b18410 Dataflow: Add flowFrom predicates to mirror flowTo. Anders Schack-Mulligen 2025-12-03 13:46:44 +01:00
  • 299fed5901 Rust: Apply fixes from code review Simon Friis Vindum 2025-12-03 13:04:54 +01:00
  • a05d0a906c Rust: Add change note for raw pointer type inference Simon Friis Vindum 2025-12-03 11:56:54 +01:00
  • c1793ab529 C#: Code quality improvement. Michael Nebel 2025-12-03 11:48:32 +01:00
  • 5784a216a2 Merge pull request #20810 from github/redsun82/update-bazel Paolo Tranquilli 2025-12-03 11:45:38 +01:00
  • 3028e5dac0 Rust: CallExpr -> Call. Geoffrey White 2025-12-02 17:21:04 +00:00
  • e710c150de Add change note Owen Mansel-Chan 2025-12-02 17:12:05 +00:00
  • a85d0ea8a3 Make tests pass Owen Mansel-Chan 2025-12-02 17:08:16 +00:00
  • 8fd8fc07b7 Add failing tests for more regex match methods Owen Mansel-Chan 2025-12-02 17:06:34 +00:00
  • 085faa2bdb Post-release preparation for codeql-cli-2.23.7 github-actions[bot] 2025-12-02 16:39:43 +00:00
  • dce6d0e222 Merge pull request #20955 from github/release-prep/2.23.7 codeql-cli/v2.23.7 codeql-cli-2.23.7 Óscar San José 2025-12-02 17:06:20 +01:00
  • 566aa8f201 Refactor regex sanitizer Owen Mansel-Chan 2025-12-02 16:04:39 +00:00
  • a045b317ac Release preparation for version 2.23.7 github-actions[bot] 2025-12-02 15:31:27 +00:00
  • 3197b50da7 C#: Address review comments. Michael Nebel 2025-12-02 16:16:29 +01:00
  • 236df0ab65 Rust: Accept changes to expected files Simon Friis Vindum 2025-12-02 15:07:54 +01:00
  • 1d9b88de8b C#: Comment back in the .NET 10 tests. Michael Nebel 2025-12-02 14:59:45 +01:00
  • ea1b0a8476 Rust: Fix path resolution for raw pointer types Simon Friis Vindum 2025-12-02 14:43:28 +01:00
  • c15e12c9ff Rust: Accept test changes Simon Friis Vindum 2025-12-02 14:36:29 +01:00
  • 785025f1e3 Rust: Type inference for raw pointers Simon Friis Vindum 2025-12-02 13:28:08 +01:00
  • 4a6ae216a4 C#: Gracefully handle non-zero exitcodes for dotnet --info. Michael Nebel 2025-11-26 13:31:45 +01:00
  • afb810cdeb Fix double space in change note Owen Mansel-Chan 2025-11-27 22:19:24 +00:00
  • 13cb10dfce Revert "JS: Split module exports into a local and global variant" revert-20885-js/local-module-exports Asger F 2025-12-02 14:19:52 +01:00
  • 5d63b6e723 C#: Accept integration test change Anders Schack-Mulligen 2025-12-02 14:01:16 +01:00
  • e52f819df0 Merge pull request #20949 from owen-mc/go/reinstate-dummy-test Owen Mansel-Chan 2025-12-02 12:55:36 +00:00
  • 67a2bced0d C#: Accept CFG dead ends for compilation errors. Anders Schack-Mulligen 2025-12-02 13:17:24 +01:00
  • 2eb2a50ccd C#: Fix enclosing DataFlowCallable of ObjectInitMethods with multiple bodies. Anders Schack-Mulligen 2025-12-02 13:11:00 +01:00
  • ba7b517a4a C#: Tweaks from review comments. Anders Schack-Mulligen 2025-11-28 11:05:04 +01:00
  • 7e4e872430 C#: Accept expected changes. Anders Schack-Mulligen 2025-11-28 10:54:08 +01:00
  • 541dce4d17 C#: Accept PrintAst index shift. Anders Schack-Mulligen 2025-11-27 14:18:17 +01:00
  • 02e5f4545a C#: Fixup test Anders Schack-Mulligen 2025-11-27 13:54:26 +01:00
  • 85121e88b4 C#: Move and rename module. Anders Schack-Mulligen 2025-11-27 11:14:55 +01:00
  • 24a575a7a5 C#: Replace initializer splitting with ObjectInitMethod. Anders Schack-Mulligen 2025-11-26 15:24:22 +01:00
  • 9414cfbd03 C#: Add extractor support for object initializer methods. Anders Schack-Mulligen 2025-11-25 15:52:34 +01:00
  • a7066ec758 C#: Add object initializer test. Anders Schack-Mulligen 2025-11-25 15:51:27 +01:00
  • 3e7a7d541b Rust: Include certain types in type inference tests Simon Friis Vindum 2025-12-02 13:14:58 +01:00
  • 6a2502c97a Rust: Add type inference tests for raw pointers Simon Friis Vindum 2025-12-02 13:00:00 +01:00
  • e9cb183670 Revert "Delete dummy.ql for now" Owen Mansel-Chan 2025-12-02 11:41:39 +00:00
  • 848677e580 Merge pull request #20917 from owen-mc/go/enable-data-flow-consistency-checks Owen Mansel-Chan 2025-12-02 10:52:47 +00:00
  • 7378fbc567 Rust: Restructure classes representing calls Tom Hvitved 2025-11-24 09:45:00 +01:00
  • 7cf3964e44 Update expectations Joe Farebrother 2025-12-01 20:27:48 +00:00
  • 666855dbd7 Shared: Improvements to content-sensitive model generation Tom Hvitved 2025-11-26 10:33:52 +01:00
  • 3e5ea5664c Rust: Add DB downgrade script Tom Hvitved 2025-12-01 13:00:01 +01:00
  • b350a000e3 Rust: Add DB upgrade script Tom Hvitved 2025-12-01 11:58:19 +01:00
  • a2782a12f2 Rust: Run codegen Tom Hvitved 2025-11-25 10:30:52 +01:00