Skip to content

Commit f79d2e0

Browse files
committed
Fix failing checks
1 parent 6b79ca6 commit f79d2e0

5 files changed

Lines changed: 4 additions & 0 deletions

File tree

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,2 @@
1+
lgtm,codescanning
2+
* The query "Expression language injection (JEXL)" (`java/jexl-expression-injection`) has been promoted from experimental to the main query pack. Its results will now appear by default. This query was originally [submitted as an experimental query by @artem-smotrakov](https://github.com/github/codeql/pull/4965)

java/ql/src/experimental/Security/CWE/CWE-094/SaferJexlExpressionEvaluationWithSandbox.java renamed to java/ql/src/Security/CWE/CWE-094/SaferJexlExpressionEvaluationWithSandbox.java

File renamed without changes.

java/ql/src/experimental/Security/CWE/CWE-094/SaferJexlExpressionEvaluationWithUberspectSandbox.java renamed to java/ql/src/Security/CWE/CWE-094/SaferJexlExpressionEvaluationWithUberspectSandbox.java

File renamed without changes.

java/ql/src/experimental/Security/CWE/CWE-094/UnsafeJexlExpressionEvaluation.java renamed to java/ql/src/Security/CWE/CWE-094/UnsafeJexlExpressionEvaluation.java

File renamed without changes.

java/ql/src/semmle/code/java/security/JexlInjection.qll

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,5 @@
1+
/** Provides classes to reason about Expression Langauge (JEXL) injection vulnerabilities. */
2+
13
import java
24
import semmle.code.java.dataflow.TaintTracking
35
private import semmle.code.java.dataflow.ExternalFlow

0 commit comments

Comments
 (0)