Skip to content

Commit d994c7c

Browse files
authored
Merge pull request #18 from trailofbits/fix-trim-misuse-df
Fix trim misuse df
2 parents fd6e8cd + 6381cb5 commit d994c7c

File tree

5 files changed

+78
-6
lines changed

5 files changed

+78
-6
lines changed

cpp/src/codeql-pack.lock.yml

Lines changed: 21 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,24 @@
11
---
22
lockVersion: 1.0.0
3-
dependencies: {}
3+
dependencies:
4+
codeql/cpp-all:
5+
version: 3.0.0
6+
codeql/dataflow:
7+
version: 1.1.7
8+
codeql/mad:
9+
version: 1.0.13
10+
codeql/rangeanalysis:
11+
version: 1.0.13
12+
codeql/ssa:
13+
version: 1.0.13
14+
codeql/tutorial:
15+
version: 1.0.13
16+
codeql/typeflow:
17+
version: 1.0.13
18+
codeql/typetracking:
19+
version: 1.0.13
20+
codeql/util:
21+
version: 2.0.0
22+
codeql/xml:
23+
version: 1.0.13
424
compiled: false

cpp/test/codeql-pack.lock.yml

Lines changed: 21 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,24 @@
11
---
22
lockVersion: 1.0.0
3-
dependencies: {}
3+
dependencies:
4+
codeql/cpp-all:
5+
version: 3.0.0
6+
codeql/dataflow:
7+
version: 1.1.7
8+
codeql/mad:
9+
version: 1.0.13
10+
codeql/rangeanalysis:
11+
version: 1.0.13
12+
codeql/ssa:
13+
version: 1.0.13
14+
codeql/tutorial:
15+
version: 1.0.13
16+
codeql/typeflow:
17+
version: 1.0.13
18+
codeql/typetracking:
19+
version: 1.0.13
20+
codeql/util:
21+
version: 2.0.0
22+
codeql/xml:
23+
version: 1.0.13
424
compiled: false

go/src/codeql-pack.lock.yml

Lines changed: 17 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,20 @@
11
---
22
lockVersion: 1.0.0
3-
dependencies: {}
3+
dependencies:
4+
codeql/dataflow:
5+
version: 1.1.7
6+
codeql/go-all:
7+
version: 3.0.0
8+
codeql/mad:
9+
version: 1.0.13
10+
codeql/ssa:
11+
version: 1.0.13
12+
codeql/threat-models:
13+
version: 1.0.13
14+
codeql/tutorial:
15+
version: 1.0.13
16+
codeql/typetracking:
17+
version: 1.0.13
18+
codeql/util:
19+
version: 2.0.0
420
compiled: false

go/src/security/TrimMisuse/TrimMisuse.ql

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@
1111
*/
1212

1313
import go
14-
import DataFlow2
14+
import semmle.go.dataflow.DataFlow
1515

1616
/*
1717
* Flows from a string to TrimFamilyCall cutSet argument
@@ -32,7 +32,7 @@ module Trim2ndArgFlow = DataFlow::Global<Trim2ndArgConfig>;
3232
/*
3333
* Calls to Trim methods that we are interested in
3434
*/
35-
class TrimFamilyCall extends CallNode {
35+
class TrimFamilyCall extends DataFlow::CallNode {
3636
TrimFamilyCall() {
3737
this.getTarget().hasQualifiedName("strings", ["TrimRight", "TrimLeft", "Trim"])
3838
or

go/test/codeql-pack.lock.yml

Lines changed: 17 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,20 @@
11
---
22
lockVersion: 1.0.0
3-
dependencies: {}
3+
dependencies:
4+
codeql/dataflow:
5+
version: 1.1.7
6+
codeql/go-all:
7+
version: 3.0.0
8+
codeql/mad:
9+
version: 1.0.13
10+
codeql/ssa:
11+
version: 1.0.13
12+
codeql/threat-models:
13+
version: 1.0.13
14+
codeql/tutorial:
15+
version: 1.0.13
16+
codeql/typetracking:
17+
version: 1.0.13
18+
codeql/util:
19+
version: 2.0.0
420
compiled: false

0 commit comments

Comments
 (0)