-
Notifications
You must be signed in to change notification settings - Fork 395
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merge Develop into Release #3510
Commits on Sep 18, 2024
-
Be consistent with using .fixed.test.yaml not .test.fixed.yaml (#3471)
test plan: make test
Configuration menu - View commit details
-
Copy full SHA for b756568 - Browse repository at this point
Copy the full SHA b756568View commit details
Commits on Sep 19, 2024
-
* PHP tainted exec When user input is passed to a function that executes a shell command, without escaping. * Correct message string YAML operator Co-authored-by: Pieter De Cremer (Semgrep) <pieter@r2c.dev> --------- Co-authored-by: Pieter De Cremer (Semgrep) <pieter@r2c.dev> Co-authored-by: Lewis <LewisArdern@live.co.uk>
Configuration menu - View commit details
-
Copy full SHA for 6d1b466 - Browse repository at this point
Copy the full SHA 6d1b466View commit details -
Upload dockerd socket mount detection rule and test file (#3360)
* Upload dockerd socket mount detection rule and test file * Update dockerd-socket-mount.dockerfile * Update documentbuilderfactory-disallow-doctype-decl-missing.yaml Update the rule for checking if FEATURE_SECURE_PROCESSING is set to TRUE for DocumentBuilderFactory object. * Revert "Update documentbuilderfactory-disallow-doctype-decl-missing.yaml" This reverts commit c1e2281. --------- Co-authored-by: Pieter De Cremer (Semgrep) <pieter@r2c.dev>
Configuration menu - View commit details
-
Copy full SHA for 7427b82 - Browse repository at this point
Copy the full SHA 7427b82View commit details -
Switch to osemgrep test --experimental (from 3min to 21s) (#3472)
* Switch to osemgrep test --experimental test plan: wait for green CI check * comment * comments
Configuration menu - View commit details
-
Copy full SHA for be389ac - Browse repository at this point
Copy the full SHA be389acView commit details -
remove fingerprints/fingerprints.yaml (#3474)
* remove fingerprints/fingerprints.yaml No idea what this file is, but it's annoying because we have to skip it in many scripts because it does not contain regular rules and target test files. Let's just remove it to simplify things. test plan: wait for green CI checks * remove every use of fingerprints (each time it was to skip the dir)
Configuration menu - View commit details
-
Copy full SHA for 46fc340 - Browse repository at this point
Copy the full SHA 46fc340View commit details
Commits on Sep 23, 2024
-
chore: Fix some wrong annotations (#3476)
test plan: osemgrep test on those dirs do not report any more warnings about wrong annotations
Configuration menu - View commit details
-
Copy full SHA for 8ce8781 - Browse repository at this point
Copy the full SHA 8ce8781View commit details -
Run osemgrep test --pro on apex/ and elixir/ too (#3478)
test plan: wait for green CI checks
Configuration menu - View commit details
-
Copy full SHA for de1405b - Browse repository at this point
Copy the full SHA de1405bView commit details
Commits on Sep 25, 2024
-
Named metavariable bug was fixed (#3477)
* Named metavariable bug for CMD-like instructions using array syntax was fixed * Update the expected autofixes
Configuration menu - View commit details
-
Copy full SHA for 959c893 - Browse repository at this point
Copy the full SHA 959c893View commit details -
Configuration menu - View commit details
-
Copy full SHA for 81e40c5 - Browse repository at this point
Copy the full SHA 81e40c5View commit details
Commits on Sep 26, 2024
-
Configuration menu - View commit details
-
Copy full SHA for ecba02c - Browse repository at this point
Copy the full SHA ecba02cView commit details
Commits on Oct 5, 2024
-
Rule: OpenAI isConsequential flag set to false for state changing ope…
…ration in OpenAPI spec (#3446) * Rule: OpenAI isConsequential flag set to false for state changing operation in OpenAPI spec * set subcategory to audit instead of vuln * alternative approach --------- Co-authored-by: Pieter De Cremer (Semgrep) <pieter@r2c.dev>
Configuration menu - View commit details
-
Copy full SHA for ed75fb1 - Browse repository at this point
Copy the full SHA ed75fb1View commit details
Commits on Oct 7, 2024
-
Include GitHub discussions as user input source. (#3483)
Co-authored-by: Vasilii Ermilov <inkz@xakep.ru>
Configuration menu - View commit details
-
Copy full SHA for 6364d2b - Browse repository at this point
Copy the full SHA 6364d2bView commit details -
Exclude Slack webhook sample URL (#3482)
* Exclude Slack webhook sample URL. * Test case for excluding Slack webhook sample URL. --------- Co-authored-by: Vasilii Ermilov <inkz@xakep.ru>
Configuration menu - View commit details
-
Copy full SHA for ca45011 - Browse repository at this point
Copy the full SHA ca45011View commit details -
New Published Rules - semgrep.check-is-none-explicitly (#3480)
* add semgrep/check-is-none-explicitly.yaml * add semgrep/check-is-none-explicitly.py * move new rule to correctness directory --------- Co-authored-by: Clara McCreery <clara@semgrep.com> Co-authored-by: Vasilii <inkz@xakep.ru>
Configuration menu - View commit details
-
Copy full SHA for 5aa4f20 - Browse repository at this point
Copy the full SHA 5aa4f20View commit details -
todoruleid: -> proruleid: for solidity test (#3484)
test plan: osemgrep test --pro solidity
Configuration menu - View commit details
-
Copy full SHA for 0da2dce - Browse repository at this point
Copy the full SHA 0da2dceView commit details
Commits on Oct 15, 2024
-
Configuration menu - View commit details
-
Copy full SHA for b4eb008 - Browse repository at this point
Copy the full SHA b4eb008View commit details -
Add rules around Node.js crypto module (#3357)
Co-authored-by: Pieter De Cremer (Semgrep) <pieter@r2c.dev>
Configuration menu - View commit details
-
Copy full SHA for c865e0c - Browse repository at this point
Copy the full SHA c865e0cView commit details -
Configuration menu - View commit details
-
Copy full SHA for 153588f - Browse repository at this point
Copy the full SHA 153588fView commit details
Commits on Oct 17, 2024
-
Configuration menu - View commit details
-
Copy full SHA for cd697bc - Browse repository at this point
Copy the full SHA cd697bcView commit details
Commits on Oct 18, 2024
-
Fix for osemgrep test --pro with DeepScan too (often deepruleid: -> d…
…eeptodoruleid:) (#3490) * Fix for osemgrep test --pro with DeepScan too Mostly some deepruleid: -> deeptodoruleid: as unfortunately the engine is still not good enough to find them test plan: osemgrep-pro test --pro . * fix
Configuration menu - View commit details
-
Copy full SHA for 5583c92 - Browse repository at this point
Copy the full SHA 5583c92View commit details -
Configuration menu - View commit details
-
Copy full SHA for 966d1ba - Browse repository at this point
Copy the full SHA 966d1baView commit details
Commits on Oct 21, 2024
-
Fix annots for osemgrep test --pro with DeepScan (#3492)
test plan: osemgrep-pro test --pro semgrep-rules/
Configuration menu - View commit details
-
Copy full SHA for 97bd5b0 - Browse repository at this point
Copy the full SHA 97bd5b0View commit details
Commits on Oct 22, 2024
-
Remove scripts/run-test to simplify, call just osemgrep test (#3493)
* Remove scripts/run-test to simplify, call just osemgrep test It has been almost a month that we run both osemgrep test and pysemgrep --test and no complaints, so let's remove the use of pysemgrep --test so we can then remove the corresponding python code in pysemgrep. test plan: make validate make test-only wait for green CI checks * more
Configuration menu - View commit details
-
Copy full SHA for 0bba56c - Browse repository at this point
Copy the full SHA 0bba56cView commit details
Commits on Oct 24, 2024
-
remove redundant rules for HTML templates (#3349)
* remove redundant rules for HTML templates * Delete python/django/security/audit/xss/var-in-script-tag.html * Delete python/django/security/audit/xss/var-in-script-tag.yaml --------- Co-authored-by: Claudio <claudio@r2c.dev>
Configuration menu - View commit details
-
Copy full SHA for aa55fb5 - Browse repository at this point
Copy the full SHA aa55fb5View commit details -
Update stacktrace-disclosure rule and test (#3495)
* Update stacktrace-disclosure.cs * Update stacktrace-disclosure.yaml
Configuration menu - View commit details
-
Copy full SHA for e91dd3f - Browse repository at this point
Copy the full SHA e91dd3fView commit details -
Remove redundant rule python.lang.security.audit.ftplib (#3496)
* Remove redundant rule python.lang.security.audit.ftplib python.lang.security.audit.ftplib.ftplib is best replaced by python.lang.security.audit.insecure-transport.ftplib.use-ftp-tls.use-ftp-tls * Update use-ftp-tls.yaml
Configuration menu - View commit details
-
Copy full SHA for 157ae47 - Browse repository at this point
Copy the full SHA 157ae47View commit details
Commits on Oct 29, 2024
-
Delete python/lang/security/audit/ftplib.py
Should have been deleted in #3496, causing semgrep/semgrep-proprietary#2505 to fail
Configuration menu - View commit details
-
Copy full SHA for 116b0bd - Browse repository at this point
Copy the full SHA 116b0bdView commit details -
Merge pull request #3504 from semgrep/austin/remove-ftplib-py
Delete python/lang/security/audit/ftplib.py
Configuration menu - View commit details
-
Copy full SHA for 2ad051c - Browse repository at this point
Copy the full SHA 2ad051cView commit details
Commits on Nov 4, 2024
-
Configuration menu - View commit details
-
Copy full SHA for 178f46e - Browse repository at this point
Copy the full SHA 178f46eView commit details -
Configuration menu - View commit details
-
Copy full SHA for 73d6cde - Browse repository at this point
Copy the full SHA 73d6cdeView commit details