Skip to content

Commit 2952c0d

Browse files
authored
Merge pull request #19507 from michaelnebel/removehardcodedpassword
Exclude some queries from query suites by lowering their precision.
2 parents 789e881 + dabeddb commit 2952c0d

File tree

41 files changed

+50
-36
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

41 files changed

+50
-36
lines changed

csharp/ql/integration-tests/posix/query-suite/csharp-security-and-quality.qls.expected

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -38,7 +38,6 @@ ql/csharp/ql/src/Concurrency/SynchSetUnsynchGet.ql
3838
ql/csharp/ql/src/Concurrency/UnsafeLazyInitialization.ql
3939
ql/csharp/ql/src/Concurrency/UnsynchronizedStaticAccess.ql
4040
ql/csharp/ql/src/Configuration/EmptyPasswordInConfigurationFile.ql
41-
ql/csharp/ql/src/Configuration/PasswordInConfigurationFile.ql
4241
ql/csharp/ql/src/Dead Code/DeadStoreOfLocal.ql
4342
ql/csharp/ql/src/Diagnostics/CompilerError.ql
4443
ql/csharp/ql/src/Diagnostics/CompilerMessage.ql
@@ -146,8 +145,6 @@ ql/csharp/ql/src/Security Features/CWE-639/InsecureDirectObjectReference.ql
146145
ql/csharp/ql/src/Security Features/CWE-643/XPathInjection.ql
147146
ql/csharp/ql/src/Security Features/CWE-730/ReDoS.ql
148147
ql/csharp/ql/src/Security Features/CWE-730/RegexInjection.ql
149-
ql/csharp/ql/src/Security Features/CWE-798/HardcodedConnectionString.ql
150-
ql/csharp/ql/src/Security Features/CWE-798/HardcodedCredentials.ql
151148
ql/csharp/ql/src/Security Features/CWE-807/ConditionalBypass.ql
152149
ql/csharp/ql/src/Security Features/CookieWithOverlyBroadDomain.ql
153150
ql/csharp/ql/src/Security Features/CookieWithOverlyBroadPath.ql

csharp/ql/integration-tests/posix/query-suite/csharp-security-extended.qls.expected

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,4 @@
11
ql/csharp/ql/src/Configuration/EmptyPasswordInConfigurationFile.ql
2-
ql/csharp/ql/src/Configuration/PasswordInConfigurationFile.ql
32
ql/csharp/ql/src/Diagnostics/CompilerError.ql
43
ql/csharp/ql/src/Diagnostics/CompilerMessage.ql
54
ql/csharp/ql/src/Diagnostics/DiagnosticExtractionErrors.ql
@@ -49,8 +48,6 @@ ql/csharp/ql/src/Security Features/CWE-639/InsecureDirectObjectReference.ql
4948
ql/csharp/ql/src/Security Features/CWE-643/XPathInjection.ql
5049
ql/csharp/ql/src/Security Features/CWE-730/ReDoS.ql
5150
ql/csharp/ql/src/Security Features/CWE-730/RegexInjection.ql
52-
ql/csharp/ql/src/Security Features/CWE-798/HardcodedConnectionString.ql
53-
ql/csharp/ql/src/Security Features/CWE-798/HardcodedCredentials.ql
5451
ql/csharp/ql/src/Security Features/CWE-807/ConditionalBypass.ql
5552
ql/csharp/ql/src/Security Features/CookieWithOverlyBroadDomain.ql
5653
ql/csharp/ql/src/Security Features/CookieWithOverlyBroadPath.ql

csharp/ql/integration-tests/posix/query-suite/not_included_in_qls.expected

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -26,6 +26,7 @@ ql/csharp/ql/src/Bad Practices/Naming Conventions/DefaultControlNames.ql
2626
ql/csharp/ql/src/Bad Practices/Naming Conventions/VariableNameTooShort.ql
2727
ql/csharp/ql/src/Bad Practices/UseOfHtmlInputHidden.ql
2828
ql/csharp/ql/src/Bad Practices/UseOfSystemOutputStream.ql
29+
ql/csharp/ql/src/Configuration/PasswordInConfigurationFile.ql
2930
ql/csharp/ql/src/Dead Code/DeadRefTypes.ql
3031
ql/csharp/ql/src/Dead Code/NonAssignedFields.ql
3132
ql/csharp/ql/src/Dead Code/UnusedField.ql
@@ -89,6 +90,8 @@ ql/csharp/ql/src/Security Features/CWE-321/HardcodedSymmetricEncryptionKey.ql
8990
ql/csharp/ql/src/Security Features/CWE-327/DontInstallRootCert.ql
9091
ql/csharp/ql/src/Security Features/CWE-502/UnsafeDeserialization.ql
9192
ql/csharp/ql/src/Security Features/CWE-611/UseXmlSecureResolver.ql
93+
ql/csharp/ql/src/Security Features/CWE-798/HardcodedConnectionString.ql
94+
ql/csharp/ql/src/Security Features/CWE-798/HardcodedCredentials.ql
9295
ql/csharp/ql/src/Security Features/CWE-838/InappropriateEncoding.ql
9396
ql/csharp/ql/src/Useless code/PointlessForwardingMethod.ql
9497
ql/csharp/ql/src/definitions.ql

csharp/ql/src/Configuration/PasswordInConfigurationFile.ql

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@
44
* @kind problem
55
* @problem.severity warning
66
* @security-severity 7.5
7-
* @precision medium
7+
* @precision low
88
* @id cs/password-in-configuration
99
* @tags security
1010
* external/cwe/cwe-013

csharp/ql/src/Security Features/CWE-798/HardcodedConnectionString.ql

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@
44
* @kind path-problem
55
* @problem.severity error
66
* @security-severity 9.8
7-
* @precision medium
7+
* @precision low
88
* @id cs/hardcoded-connection-string-credentials
99
* @tags security
1010
* external/cwe/cwe-259

csharp/ql/src/Security Features/CWE-798/HardcodedCredentials.ql

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@
44
* @kind path-problem
55
* @problem.severity error
66
* @security-severity 9.8
7-
* @precision medium
7+
* @precision low
88
* @id cs/hardcoded-credentials
99
* @tags security
1010
* external/cwe/cwe-259
Lines changed: 4 additions & 0 deletions

go/ql/integration-tests/query-suite/go-security-and-quality.qls.expected

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -50,6 +50,5 @@ ql/go/ql/src/Security/CWE-640/EmailInjection.ql
5050
ql/go/ql/src/Security/CWE-643/XPathInjection.ql
5151
ql/go/ql/src/Security/CWE-681/IncorrectIntegerConversionQuery.ql
5252
ql/go/ql/src/Security/CWE-770/UncontrolledAllocationSize.ql
53-
ql/go/ql/src/Security/CWE-798/HardcodedCredentials.ql
5453
ql/go/ql/src/Security/CWE-918/RequestForgery.ql
5554
ql/go/ql/src/Summary/LinesOfCode.ql

go/ql/integration-tests/query-suite/go-security-extended.qls.expected

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -28,6 +28,5 @@ ql/go/ql/src/Security/CWE-640/EmailInjection.ql
2828
ql/go/ql/src/Security/CWE-643/XPathInjection.ql
2929
ql/go/ql/src/Security/CWE-681/IncorrectIntegerConversionQuery.ql
3030
ql/go/ql/src/Security/CWE-770/UncontrolledAllocationSize.ql
31-
ql/go/ql/src/Security/CWE-798/HardcodedCredentials.ql
3231
ql/go/ql/src/Security/CWE-918/RequestForgery.ql
3332
ql/go/ql/src/Summary/LinesOfCode.ql

go/ql/integration-tests/query-suite/not_included_in_qls.expected

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,7 @@ ql/go/ql/src/Security/CWE-020/UntrustedDataToExternalAPI.ql
66
ql/go/ql/src/Security/CWE-020/UntrustedDataToUnknownExternalAPI.ql
77
ql/go/ql/src/Security/CWE-078/StoredCommand.ql
88
ql/go/ql/src/Security/CWE-079/StoredXss.ql
9+
ql/go/ql/src/Security/CWE-798/HardcodedCredentials.ql
910
ql/go/ql/src/definitions.ql
1011
ql/go/ql/src/experimental/CWE-090/LDAPInjection.ql
1112
ql/go/ql/src/experimental/CWE-1004/CookieWithoutHttpOnly.ql

0 commit comments

Comments
 (0)