FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

Java: Promote experimental XXE sinks by atorralba · Pull Request #12932 · github/codeql · GitHub

/ codeql Public

Java: Promote experimental XXE sinks - #12932

Merged
atorralba merged 7 commits into
github:mainfrom
atorralba:atorralba/java/promote-xxe-experimental-sinks
May 17, 2023
Merged

Java: Promote experimental XXE sinks#12932
atorralba merged 7 commits into
github:mainfrom
atorralba:atorralba/java/promote-xxe-experimental-sinks

Conversation

Copy link
Copy Markdown
Contributor

Promotes the experimental XXE sinks submitted in #6564. Also refactors the XXE tests to use InlineFlowTest.

@aschackmull: In the first commit, I moved a class ConstantStringExpr that was present in XmlParsers.qll to RangeUtils.qll because I needed to use it in other files. I think it makes sense for it to be there, but please let me know if you disagree or if you foresee any performance issues.

Copy link
Copy Markdown
Contributor

QHelp previews:

Copy link
Copy Markdown
Contributor

In the first commit, I moved a class ConstantStringExpr that was present in XmlParsers.qll to RangeUtils.qll because I needed to use it in other files

LGTM

Copy link
Copy Markdown
Contributor Author

DCA is uneventful.

egregius313 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Choose a reason Spam Abuse Off Topic Outdated Duplicate Resolved Low Quality

LGTM

atorralba merged commit 1b06bf1 into github:main May 17, 2023
atorralba deleted the atorralba/java/promote-xxe-experimental-sinks branch May 17, 2023 15:55
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants


Back | FazBrowse Home | New Git URL