Skip to content

Commit 28eb229

Browse files
authored
Merge pull request #97 from GitHubSecurityLab/updatedependencies-2.20.1
Update dependencies to packs shipped with 2.20.1
2 parents 601dade + eea5e3a commit 28eb229

File tree

65 files changed

+4180
-4364
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

65 files changed

+4180
-4364
lines changed

cpp/lib/codeql-pack.lock.yml

Lines changed: 10 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -2,23 +2,23 @@
22
lockVersion: 1.0.0
33
dependencies:
44
codeql/cpp-all:
5-
version: 2.1.0
5+
version: 3.1.0
66
codeql/dataflow:
7-
version: 1.1.5
7+
version: 1.1.8
88
codeql/mad:
9-
version: 1.0.11
9+
version: 1.0.14
1010
codeql/rangeanalysis:
11-
version: 1.0.11
11+
version: 1.0.14
1212
codeql/ssa:
13-
version: 1.0.11
13+
version: 1.0.14
1414
codeql/tutorial:
15-
version: 1.0.11
15+
version: 1.0.14
1616
codeql/typeflow:
17-
version: 1.0.11
17+
version: 1.0.14
1818
codeql/typetracking:
19-
version: 1.0.11
19+
version: 1.0.14
2020
codeql/util:
21-
version: 1.0.11
21+
version: 2.0.1
2222
codeql/xml:
23-
version: 1.0.11
23+
version: 1.0.14
2424
compiled: false

cpp/src/codeql-pack.lock.yml

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -2,27 +2,27 @@
22
lockVersion: 1.0.0
33
dependencies:
44
codeql/cpp-all:
5-
version: 2.1.0
5+
version: 3.1.0
66
codeql/cpp-queries:
7-
version: 1.2.6
7+
version: 1.3.1
88
codeql/dataflow:
9-
version: 1.1.5
9+
version: 1.1.8
1010
codeql/mad:
11-
version: 1.0.11
11+
version: 1.0.14
1212
codeql/rangeanalysis:
13-
version: 1.0.11
13+
version: 1.0.14
1414
codeql/ssa:
15-
version: 1.0.11
15+
version: 1.0.14
1616
codeql/suite-helpers:
17-
version: 1.0.11
17+
version: 1.0.14
1818
codeql/tutorial:
19-
version: 1.0.11
19+
version: 1.0.14
2020
codeql/typeflow:
21-
version: 1.0.11
21+
version: 1.0.14
2222
codeql/typetracking:
23-
version: 1.0.11
23+
version: 1.0.14
2424
codeql/util:
25-
version: 1.0.11
25+
version: 2.0.1
2626
codeql/xml:
27-
version: 1.0.11
27+
version: 1.0.14
2828
compiled: false

cpp/test/codeql-pack.lock.yml

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -2,27 +2,27 @@
22
lockVersion: 1.0.0
33
dependencies:
44
codeql/cpp-all:
5-
version: 2.1.0
5+
version: 3.1.0
66
codeql/cpp-queries:
7-
version: 1.2.6
7+
version: 1.3.1
88
codeql/dataflow:
9-
version: 1.1.5
9+
version: 1.1.8
1010
codeql/mad:
11-
version: 1.0.11
11+
version: 1.0.14
1212
codeql/rangeanalysis:
13-
version: 1.0.11
13+
version: 1.0.14
1414
codeql/ssa:
15-
version: 1.0.11
15+
version: 1.0.14
1616
codeql/suite-helpers:
17-
version: 1.0.11
17+
version: 1.0.14
1818
codeql/tutorial:
19-
version: 1.0.11
19+
version: 1.0.14
2020
codeql/typeflow:
21-
version: 1.0.11
21+
version: 1.0.14
2222
codeql/typetracking:
23-
version: 1.0.11
23+
version: 1.0.14
2424
codeql/util:
25-
version: 1.0.11
25+
version: 2.0.1
2626
codeql/xml:
27-
version: 1.0.11
27+
version: 1.0.14
2828
compiled: false

csharp/lib/codeql-pack.lock.yml

Lines changed: 10 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -2,23 +2,23 @@
22
lockVersion: 1.0.0
33
dependencies:
44
codeql/controlflow:
5-
version: 1.0.11
5+
version: 1.0.14
66
codeql/csharp-all:
7-
version: 3.1.0
7+
version: 4.0.1
88
codeql/dataflow:
9-
version: 1.1.5
9+
version: 1.1.8
1010
codeql/mad:
11-
version: 1.0.11
11+
version: 1.0.14
1212
codeql/ssa:
13-
version: 1.0.11
13+
version: 1.0.14
1414
codeql/threat-models:
15-
version: 1.0.11
15+
version: 1.0.14
1616
codeql/tutorial:
17-
version: 1.0.11
17+
version: 1.0.14
1818
codeql/typetracking:
19-
version: 1.0.11
19+
version: 1.0.14
2020
codeql/util:
21-
version: 1.0.11
21+
version: 2.0.1
2222
codeql/xml:
23-
version: 1.0.11
23+
version: 1.0.14
2424
compiled: false

csharp/src/audit/explore/Dependencies.ql

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@
99

1010
private import csharp
1111
private import semmle.code.csharp.dispatch.Dispatch
12-
private import Telemetry.ExternalApi
12+
private import semmle.code.csharp.telemetry.ExternalApi
1313

1414
private predicate getRelevantUsages(string namespace, int usages) {
1515
usages =

csharp/src/codeql-pack.lock.yml

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -2,27 +2,27 @@
22
lockVersion: 1.0.0
33
dependencies:
44
codeql/controlflow:
5-
version: 1.0.11
5+
version: 1.0.14
66
codeql/csharp-all:
7-
version: 3.1.0
7+
version: 4.0.1
88
codeql/csharp-queries:
9-
version: 1.0.11
9+
version: 1.0.14
1010
codeql/dataflow:
11-
version: 1.1.5
11+
version: 1.1.8
1212
codeql/mad:
13-
version: 1.0.11
13+
version: 1.0.14
1414
codeql/ssa:
15-
version: 1.0.11
15+
version: 1.0.14
1616
codeql/suite-helpers:
17-
version: 1.0.11
17+
version: 1.0.14
1818
codeql/threat-models:
19-
version: 1.0.11
19+
version: 1.0.14
2020
codeql/tutorial:
21-
version: 1.0.11
21+
version: 1.0.14
2222
codeql/typetracking:
23-
version: 1.0.11
23+
version: 1.0.14
2424
codeql/util:
25-
version: 1.0.11
25+
version: 2.0.1
2626
codeql/xml:
27-
version: 1.0.11
27+
version: 1.0.14
2828
compiled: false

csharp/src/library_sources/ExternalAPIsQuery.qll

Lines changed: 0 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -98,19 +98,6 @@ class ExternalApiDataNode extends DataFlow::Node {
9898
}
9999
}
100100

101-
/**
102-
* DEPRECATED: Use `RemoteSourceToExternalApi` instead.
103-
*
104-
* A configuration for tracking flow from `RemoteFlowSource`s to `ExternalApiDataNode`s.
105-
*/
106-
deprecated class UntrustedDataToExternalApiConfig extends TaintTracking::Configuration {
107-
UntrustedDataToExternalApiConfig() { this = "UntrustedDataToExternalAPIConfig" }
108-
109-
override predicate isSource(DataFlow::Node source) { source instanceof ThreatModelFlowSource }
110-
111-
override predicate isSink(DataFlow::Node sink) { sink instanceof ExternalApiDataNode }
112-
}
113-
114101
/** A configuration for tracking flow from `ThreatModelFlowSource`s to `ExternalApiDataNode`s. */
115102
private module RemoteSourceToExternalApiConfig implements DataFlow::ConfigSig {
116103
predicate isSource(DataFlow::Node source) { source instanceof ActiveThreatModelSource }

csharp/src/security/dataflow/flowsources/AuthCookie.qll

Lines changed: 0 additions & 55 deletions
Original file line numberDiff line numberDiff line change
@@ -114,61 +114,6 @@ Expr getAValueForProp(ObjectCreation create, Assignment a, string prop) {
114114
*/
115115
predicate isPropertySet(ObjectCreation oc, string prop) { exists(getAValueForProp(oc, _, prop)) }
116116

117-
/**
118-
* Tracks if a callback used in `OnAppendCookie` sets a cookie property to `true`.
119-
*/
120-
abstract deprecated private class OnAppendCookieTrackingConfig extends DataFlow::Configuration {
121-
bindingset[this]
122-
OnAppendCookieTrackingConfig() { any() }
123-
124-
/**
125-
* Specifies the cookie property name to track.
126-
*/
127-
abstract string propertyName();
128-
129-
override predicate isSource(DataFlow::Node source) {
130-
exists(PropertyWrite pw, Assignment delegateAssign, Callable c |
131-
pw.getProperty().getName() = "OnAppendCookie" and
132-
pw.getProperty().getDeclaringType() instanceof MicrosoftAspNetCoreBuilderCookiePolicyOptions and
133-
delegateAssign.getLValue() = pw and
134-
(
135-
exists(LambdaExpr lambda |
136-
delegateAssign.getRValue() = lambda and
137-
lambda = c
138-
)
139-
or
140-
exists(DelegateCreation delegate |
141-
delegateAssign.getRValue() = delegate and
142-
delegate.getArgument().(CallableAccess).getTarget() = c
143-
)
144-
) and
145-
c.getParameter(0) = source.asParameter()
146-
)
147-
}
148-
149-
override predicate isSink(DataFlow::Node sink) {
150-
exists(PropertyWrite pw, Assignment a |
151-
pw.getProperty().getDeclaringType() instanceof MicrosoftAspNetCoreHttpCookieOptions and
152-
pw.getProperty().getName() = this.propertyName() and
153-
a.getLValue() = pw and
154-
exists(Expr val |
155-
DataFlow::localExprFlow(val, a.getRValue()) and
156-
val.getValue() = "true"
157-
) and
158-
sink.asExpr() = pw.getQualifier()
159-
)
160-
}
161-
162-
override predicate isAdditionalFlowStep(DataFlow::Node node1, DataFlow::Node node2) {
163-
node2.asExpr() =
164-
any(PropertyRead pr |
165-
pr.getQualifier() = node1.asExpr() and
166-
pr.getProperty().getDeclaringType() instanceof
167-
MicrosoftAspNetCoreCookiePolicyAppendCookieContext
168-
)
169-
}
170-
}
171-
172117
private signature string propertyName();
173118

174119
/**

csharp/test/codeql-pack.lock.yml

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -2,27 +2,27 @@
22
lockVersion: 1.0.0
33
dependencies:
44
codeql/controlflow:
5-
version: 1.0.11
5+
version: 1.0.14
66
codeql/csharp-all:
7-
version: 3.1.0
7+
version: 4.0.1
88
codeql/csharp-queries:
9-
version: 1.0.11
9+
version: 1.0.14
1010
codeql/dataflow:
11-
version: 1.1.5
11+
version: 1.1.8
1212
codeql/mad:
13-
version: 1.0.11
13+
version: 1.0.14
1414
codeql/ssa:
15-
version: 1.0.11
15+
version: 1.0.14
1616
codeql/suite-helpers:
17-
version: 1.0.11
17+
version: 1.0.14
1818
codeql/threat-models:
19-
version: 1.0.11
19+
version: 1.0.14
2020
codeql/tutorial:
21-
version: 1.0.11
21+
version: 1.0.14
2222
codeql/typetracking:
23-
version: 1.0.11
23+
version: 1.0.14
2424
codeql/util:
25-
version: 1.0.11
25+
version: 2.0.1
2626
codeql/xml:
27-
version: 1.0.11
27+
version: 1.0.14
2828
compiled: false

go/lib/codeql-pack.lock.yml

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -2,19 +2,19 @@
22
lockVersion: 1.0.0
33
dependencies:
44
codeql/dataflow:
5-
version: 1.1.5
5+
version: 1.1.8
66
codeql/go-all:
7-
version: 2.1.2
7+
version: 3.0.1
88
codeql/mad:
9-
version: 1.0.11
9+
version: 1.0.14
1010
codeql/ssa:
11-
version: 1.0.11
11+
version: 1.0.14
1212
codeql/threat-models:
13-
version: 1.0.11
13+
version: 1.0.14
1414
codeql/tutorial:
15-
version: 1.0.11
15+
version: 1.0.14
1616
codeql/typetracking:
17-
version: 1.0.11
17+
version: 1.0.14
1818
codeql/util:
19-
version: 1.0.11
19+
version: 2.0.1
2020
compiled: false

0 commit comments

Comments
 (0)