Skip to content

Commit 76375f8

Browse files
committed
Merge remote-tracking branch 'origin/main' into henrymercer/semmle-code-noop-merge
2 parents 013b4c8 + 6a6a63e commit 76375f8

File tree

187 files changed

+5302
-746
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

187 files changed

+5302
-746
lines changed

.github/workflows/go-tests.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,7 @@ on:
44
paths:
55
- "go/**"
66
- .github/workflows/go-tests.yml
7+
- codeql-workspace.yml
78
jobs:
89

910
test-linux:

.github/workflows/js-ml-tests.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,13 +5,15 @@ on:
55
paths:
66
- "javascript/ql/experimental/adaptivethreatmodeling/**"
77
- .github/workflows/js-ml-tests.yml
8+
- codeql-workspace.yml
89
branches:
910
- main
1011
- "rc/*"
1112
pull_request:
1213
paths:
1314
- "javascript/ql/experimental/adaptivethreatmodeling/**"
1415
- .github/workflows/js-ml-tests.yml
16+
- codeql-workspace.yml
1517
workflow_dispatch:
1618

1719
defaults:

.github/workflows/ql-for-ql-tests.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,10 +5,12 @@ on:
55
branches: [main]
66
paths:
77
- "ql/**"
8+
- codeql-workspace.yml
89
pull_request:
910
branches: [main]
1011
paths:
1112
- "ql/**"
13+
- codeql-workspace.yml
1214

1315
env:
1416
CARGO_TERM_COLOR: always

.github/workflows/ruby-build.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,13 +5,15 @@ on:
55
paths:
66
- "ruby/**"
77
- .github/workflows/ruby-build.yml
8+
- codeql-workspace.yml
89
branches:
910
- main
1011
- "rc/*"
1112
pull_request:
1213
paths:
1314
- "ruby/**"
1415
- .github/workflows/ruby-build.yml
16+
- codeql-workspace.yml
1517
branches:
1618
- main
1719
- "rc/*"

.github/workflows/ruby-qltest.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,13 +5,15 @@ on:
55
paths:
66
- "ruby/**"
77
- .github/workflows/ruby-qltest.yml
8+
- codeql-workspace.yml
89
branches:
910
- main
1011
- "rc/*"
1112
pull_request:
1213
paths:
1314
- "ruby/**"
1415
- .github/workflows/ruby-qltest.yml
16+
- codeql-workspace.yml
1517
branches:
1618
- main
1719
- "rc/*"

.github/workflows/swift-qltest.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,7 @@ on:
55
paths:
66
- "swift/**"
77
- .github/workflows/swift-qltest.yml
8+
- codeql-workspace.yml
89
branches:
910
- main
1011
defaults:

config/identical-files.json

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -525,7 +525,8 @@
525525
"csharp/ql/lib/semmle/code/csharp/dataflow/internal/AccessPathSyntax.qll",
526526
"java/ql/lib/semmle/code/java/dataflow/internal/AccessPathSyntax.qll",
527527
"javascript/ql/lib/semmle/javascript/frameworks/data/internal/AccessPathSyntax.qll",
528-
"ruby/ql/lib/codeql/ruby/dataflow/internal/AccessPathSyntax.qll"
528+
"ruby/ql/lib/codeql/ruby/dataflow/internal/AccessPathSyntax.qll",
529+
"python/ql/lib/semmle/python/frameworks/data/internal/AccessPathSyntax.qll"
529530
],
530531
"IncompleteUrlSubstringSanitization": [
531532
"javascript/ql/src/Security/CWE-020/IncompleteUrlSubstringSanitization.qll",
@@ -543,7 +544,8 @@
543544
],
544545
"ApiGraphModels": [
545546
"javascript/ql/lib/semmle/javascript/frameworks/data/internal/ApiGraphModels.qll",
546-
"ruby/ql/lib/codeql/ruby/frameworks/data/internal/ApiGraphModels.qll"
547+
"ruby/ql/lib/codeql/ruby/frameworks/data/internal/ApiGraphModels.qll",
548+
"python/ql/lib/semmle/python/frameworks/data/internal/ApiGraphModels.qll"
547549
],
548550
"TaintedFormatStringQuery Ruby/JS": [
549551
"javascript/ql/lib/semmle/javascript/security/dataflow/TaintedFormatStringQuery.qll",
Lines changed: 20 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,27 @@
11
package,sink,source,summary,sink:code,sink:html,sink:remote,sink:sql,sink:xss,source:local,summary:taint,summary:value
22
Dapper,55,,,,,,55,,,,
3+
JsonToItemsTaskFactory,,,7,,,,,,,7,
34
Microsoft.ApplicationBlocks.Data,28,,,,,,28,,,,
5+
Microsoft.CSharp,,,24,,,,,,,24,
46
Microsoft.EntityFrameworkCore,6,,,,,,6,,,,
5-
Microsoft.Extensions.Primitives,,,54,,,,,,,54,
6-
Microsoft.VisualBasic,,,4,,,,,,,,4
7+
Microsoft.Extensions.Caching.Distributed,,,15,,,,,,,15,
8+
Microsoft.Extensions.Caching.Memory,,,46,,,,,,,45,1
9+
Microsoft.Extensions.Configuration,,,83,,,,,,,80,3
10+
Microsoft.Extensions.DependencyInjection,,,62,,,,,,,62,
11+
Microsoft.Extensions.DependencyModel,,,12,,,,,,,12,
12+
Microsoft.Extensions.FileProviders,,,15,,,,,,,15,
13+
Microsoft.Extensions.FileSystemGlobbing,,,15,,,,,,,13,2
14+
Microsoft.Extensions.Hosting,,,17,,,,,,,16,1
15+
Microsoft.Extensions.Http,,,10,,,,,,,10,
16+
Microsoft.Extensions.Logging,,,37,,,,,,,37,
17+
Microsoft.Extensions.Options,,,8,,,,,,,8,
18+
Microsoft.Extensions.Primitives,,,63,,,,,,,63,
19+
Microsoft.Interop,,,27,,,,,,,27,
20+
Microsoft.NET.Build.Tasks,,,1,,,,,,,1,
21+
Microsoft.NETCore.Platforms.BuildTasks,,,4,,,,,,,4,
22+
Microsoft.VisualBasic,,,9,,,,,,,5,4
23+
Microsoft.Win32,,,8,,,,,,,8,
724
MySql.Data.MySqlClient,48,,,,,,48,,,,
825
Newtonsoft.Json,,,91,,,,,,,73,18
926
ServiceStack,194,,7,27,,75,92,,,7,
10-
System,28,3,2336,,4,,23,1,3,611,1725
27+
System,28,3,12038,,4,,23,1,3,10096,1942

csharp/documentation/library-coverage/coverage.rst

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ C# framework & library support
88

99
Framework / library,Package,Flow sources,Taint & value steps,Sinks (total),`CWE-079` :sub:`Cross-site scripting`
1010
`ServiceStack <https://servicestack.net/>`_,"``ServiceStack.*``, ``ServiceStack``",,7,194,
11-
System,"``System.*``, ``System``",3,2336,28,5
12-
Others,"``Dapper``, ``Microsoft.ApplicationBlocks.Data``, ``Microsoft.EntityFrameworkCore``, ``Microsoft.Extensions.Primitives``, ``Microsoft.VisualBasic``, ``MySql.Data.MySqlClient``, ``Newtonsoft.Json``",,149,137,
13-
Totals,,3,2492,359,5
11+
System,"``System.*``, ``System``",3,12038,28,5
12+
Others,"``Dapper``, ``JsonToItemsTaskFactory``, ``Microsoft.ApplicationBlocks.Data``, ``Microsoft.CSharp``, ``Microsoft.EntityFrameworkCore``, ``Microsoft.Extensions.Caching.Distributed``, ``Microsoft.Extensions.Caching.Memory``, ``Microsoft.Extensions.Configuration``, ``Microsoft.Extensions.DependencyInjection``, ``Microsoft.Extensions.DependencyModel``, ``Microsoft.Extensions.FileProviders``, ``Microsoft.Extensions.FileSystemGlobbing``, ``Microsoft.Extensions.Hosting``, ``Microsoft.Extensions.Http``, ``Microsoft.Extensions.Logging``, ``Microsoft.Extensions.Options``, ``Microsoft.Extensions.Primitives``, ``Microsoft.Interop``, ``Microsoft.NET.Build.Tasks``, ``Microsoft.NETCore.Platforms.BuildTasks``, ``Microsoft.VisualBasic``, ``Microsoft.Win32``, ``MySql.Data.MySqlClient``, ``Newtonsoft.Json``",,554,137,
13+
Totals,,3,12599,359,5
1414

docs/codeql/support/reusables/versions-compilers.rst

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -20,10 +20,10 @@
2020
Java,"Java 7 to 18 [4]_","javac (OpenJDK and Oracle JDK),
2121

2222
Eclipse compiler for Java (ECJ) [5]_",``.java``
23-
JavaScript,ECMAScript 2021 or lower,Not applicable,"``.js``, ``.jsx``, ``.mjs``, ``.es``, ``.es6``, ``.htm``, ``.html``, ``.xhtm``, ``.xhtml``, ``.vue``, ``.hbs``, ``.ejs``, ``.njk``, ``.json``, ``.yaml``, ``.yml``, ``.raml``, ``.xml`` [6]_"
23+
JavaScript,ECMAScript 2022 or lower,Not applicable,"``.js``, ``.jsx``, ``.mjs``, ``.es``, ``.es6``, ``.htm``, ``.html``, ``.xhtm``, ``.xhtml``, ``.vue``, ``.hbs``, ``.ejs``, ``.njk``, ``.json``, ``.yaml``, ``.yml``, ``.raml``, ``.xml`` [6]_"
2424
Python,"2.7, 3.5, 3.6, 3.7, 3.8, 3.9, 3.10",Not applicable,``.py``
2525
Ruby [7]_,"up to 3.0.2",Not applicable,"``.rb``, ``.erb``, ``.gemspec``, ``Gemfile``"
26-
TypeScript [8]_,"2.6-4.6",Standard TypeScript compiler,"``.ts``, ``.tsx``"
26+
TypeScript [8]_,"2.6-4.7",Standard TypeScript compiler,"``.ts``, ``.tsx``, ``.mts``, ``.cts``"
2727

2828
.. container:: footnote-group
2929

0 commit comments

Comments
 (0)