Skip to content

Commit e025307

Browse files
Apply suggestions from code review
Co-authored-by: Chris Smowton <[email protected]>
1 parent c367c7e commit e025307

File tree

3 files changed

+2
-4
lines changed

3 files changed

+2
-4
lines changed

java/ql/src/semmle/code/java/frameworks/JacksonQuery.qll

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,6 @@
55
import java
66
import semmle.code.java.Reflection
77
import semmle.code.java.dataflow.FlowSources
8-
import semmle.code.java.dataflow.TaintTracking
98
import semmle.code.java.dataflow.TaintTracking2
109

1110
private class ObjectMapper extends RefType {

java/ql/src/semmle/code/java/security/UnsafeDeserializationQuery.qll

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,4 @@
11
import semmle.code.java.dataflow.FlowSources
2-
import semmle.code.java.dataflow.TaintTracking2
32
import semmle.code.java.frameworks.Kryo
43
import semmle.code.java.frameworks.XStream
54
import semmle.code.java.frameworks.SnakeYaml

java/ql/test/query-tests/security/CWE-502/UnsafeDeserialization.ql

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,8 +9,8 @@ class UnsafeDeserializationTest extends InlineExpectationsTest {
99

1010
override predicate hasActualResult(Location location, string element, string tag, string value) {
1111
tag = "unsafeDeserialization" and
12-
exists(DataFlow::Node src, DataFlow::Node sink, UnsafeDeserializationConfig conf |
13-
conf.hasFlow(src, sink)
12+
exists(DataFlow::Node sink, UnsafeDeserializationConfig conf |
13+
conf.hasFlowTo(sink)
1414
|
1515
sink.getLocation() = location and
1616
element = sink.toString() and

0 commit comments

Comments
 (0)