| route-pattern | /_view_fragments/voltron/pull_requests/show/:user_id/:repository/:id/pull_request_layout(.:format) |
| route-controller | voltron_pull_requests_fragments |
| route-action | pull_request_layout |
| fetch-nonce | v2:18a2c7e0-422e-b1a2-8cdf-9cdc44fef7eb |
| current-catalog-service-hash | ae870bc5e265a340912cde392f23dad3671a0a881730ffdadd82f2f57d81641b |
| request-id | 931A:C53D0:20DD328:2E109A9:6970EF7D |
| html-safe-nonce | 31fa708e357361d7b42de790ab6dcfddd3c5da212224a456ca645c57124ccab3 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiI5MzFBOkM1M0QwOjIwREQzMjg6MkUxMDlBOTo2OTcwRUY3RCIsInZpc2l0b3JfaWQiOiIxNjM4NjU0MDIwODk4ODQ0NTQxIiwicmVnaW9uX2VkZ2UiOiJpYWQiLCJyZWdpb25fcmVuZGVyIjoiaWFkIn0= |
| visitor-hmac | 85dee9f2d1c980905fc236df5c02a1f4a315c5666a1d978d8cd7032351c29856 |
| hovercard-subject-tag | pull_request:896138354 |
| github-keyboard-shortcuts | repository,pull-request-list,pull-request-conversation,pull-request-files-changed,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | ///voltron/pull_requests_fragments/pull_request_layout |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/_view_fragments/voltron/pull_requests/show/github/codeql/8634/pull_request_layout |
| twitter:image | https://opengraph.githubassets.com/c14051093d2e8c1773c2d24f266ec1aa2dede1d8df0d91985802bb6cc1e23a90/github/codeql/pull/8634 |
| twitter:card | summary_large_image |
| og:image | https://opengraph.githubassets.com/c14051093d2e8c1773c2d24f266ec1aa2dede1d8df0d91985802bb6cc1e23a90/github/codeql/pull/8634 |
| og:image:alt | This was a draft PR to ensure we don't merge it before we have agreed with JS/Ruby about the new XmlParsing concept, but they have said good for it, so we're ready to go 👍
With this PR, I h... |
| og:image:width | 1200 |
| og:image:height | 600 |
| og:site_name | GitHub |
| og:type | object |
| og:author:username | RasmusWL |
| hostname | github.com |
| expected-hostname | github.com |
| None | b6ca3cb96fa07d8a62b95d681f9dc8fffb49a43f4fea2a5bcac6d8f5107cbf4e |
| turbo-cache-control | no-preview |
| go-import | github.com/github/codeql git https://github.com/github/codeql.git |
| octolytics-dimension-user_id | 9919 |
| octolytics-dimension-user_login | github |
| octolytics-dimension-repository_id | 143040428 |
| octolytics-dimension-repository_nwo | github/codeql |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 143040428 |
| octolytics-dimension-repository_network_root_nwo | github/codeql |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | d2448578278810c7bf94faa67651ef5adb1abfde |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
| Skip to content | https://github.com/github/codeql/pull/8634#start-of-content |
|
| https://github.com/ |
|
Sign in
| https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fgithub%2Fcodeql%2Fpull%2F8634 |
| GitHub CopilotWrite better code with AI | https://github.com/features/copilot |
| GitHub SparkBuild and deploy intelligent apps | https://github.com/features/spark |
| GitHub ModelsManage and compare prompts | https://github.com/features/models |
| MCP RegistryNewIntegrate external tools | https://github.com/mcp |
| ActionsAutomate any workflow | https://github.com/features/actions |
| CodespacesInstant dev environments | https://github.com/features/codespaces |
| IssuesPlan and track work | https://github.com/features/issues |
| Code ReviewManage code changes | https://github.com/features/code-review |
| GitHub Advanced SecurityFind and fix vulnerabilities | https://github.com/security/advanced-security |
| Code securitySecure your code as you build | https://github.com/security/advanced-security/code-security |
| Secret protectionStop leaks before they start | https://github.com/security/advanced-security/secret-protection |
| Why GitHub | https://github.com/why-github |
| Documentation | https://docs.github.com |
| Blog | https://github.blog |
| Changelog | https://github.blog/changelog |
| Marketplace | https://github.com/marketplace |
| View all features | https://github.com/features |
| Enterprises | https://github.com/enterprise |
| Small and medium teams | https://github.com/team |
| Startups | https://github.com/enterprise/startups |
| Nonprofits | https://github.com/solutions/industry/nonprofits |
| App Modernization | https://github.com/solutions/use-case/app-modernization |
| DevSecOps | https://github.com/solutions/use-case/devsecops |
| DevOps | https://github.com/solutions/use-case/devops |
| CI/CD | https://github.com/solutions/use-case/ci-cd |
| View all use cases | https://github.com/solutions/use-case |
| Healthcare | https://github.com/solutions/industry/healthcare |
| Financial services | https://github.com/solutions/industry/financial-services |
| Manufacturing | https://github.com/solutions/industry/manufacturing |
| Government | https://github.com/solutions/industry/government |
| View all industries | https://github.com/solutions/industry |
| View all solutions | https://github.com/solutions |
| AI | https://github.com/resources/articles?topic=ai |
| Software Development | https://github.com/resources/articles?topic=software-development |
| DevOps | https://github.com/resources/articles?topic=devops |
| Security | https://github.com/resources/articles?topic=security |
| View all topics | https://github.com/resources/articles |
| Customer stories | https://github.com/customer-stories |
| Events & webinars | https://github.com/resources/events |
| Ebooks & reports | https://github.com/resources/whitepapers |
| Business insights | https://github.com/solutions/executive-insights |
| GitHub Skills | https://skills.github.com |
| Documentation | https://docs.github.com |
| Customer support | https://support.github.com |
| Community forum | https://github.com/orgs/community/discussions |
| Trust center | https://github.com/trust-center |
| Partners | https://github.com/partners |
| GitHub SponsorsFund open source developers | https://github.com/sponsors |
| Security Lab | https://securitylab.github.com |
| Maintainer Community | https://maintainers.github.com |
| Accelerator | https://github.com/accelerator |
| Archive Program | https://archiveprogram.github.com |
| Topics | https://github.com/topics |
| Trending | https://github.com/trending |
| Collections | https://github.com/collections |
| Enterprise platformAI-powered developer platform | https://github.com/enterprise |
| GitHub Advanced SecurityEnterprise-grade security features | https://github.com/security/advanced-security |
| Copilot for BusinessEnterprise-grade AI features | https://github.com/features/copilot/copilot-business |
| Premium SupportEnterprise-grade 24/7 support | https://github.com/premium-support |
| Pricing | https://github.com/pricing |
| Search syntax tips | https://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax |
| documentation | https://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax |
|
Sign in
| https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fgithub%2Fcodeql%2Fpull%2F8634 |
|
Sign up
| https://github.com/signup?ref_cta=Sign+up&ref_loc=header+logged+out&ref_page=%2F%3Cuser-name%3E%2F%3Crepo-name%3E%2Fvoltron%2Fpull_requests_fragments%2Fpull_request_layout&source=header-repo&source_repo=github%2Fcodeql |
| Reload | https://github.com/github/codeql/pull/8634 |
| Reload | https://github.com/github/codeql/pull/8634 |
| Reload | https://github.com/github/codeql/pull/8634 |
|
github
| https://github.com/github |
| codeql | https://github.com/github/codeql |
|
Notifications
| https://github.com/login?return_to=%2Fgithub%2Fcodeql |
|
Fork
1.9k
| https://github.com/login?return_to=%2Fgithub%2Fcodeql |
|
Star
9.2k
| https://github.com/login?return_to=%2Fgithub%2Fcodeql |
|
Code
| https://github.com/github/codeql |
|
Issues
919
| https://github.com/github/codeql/issues |
|
Pull requests
358
| https://github.com/github/codeql/pulls |
|
Discussions
| https://github.com/github/codeql/discussions |
|
Actions
| https://github.com/github/codeql/actions |
|
Projects
0
| https://github.com/github/codeql/projects |
|
Models
| https://github.com/github/codeql/models |
|
Security
Uh oh!
There was an error while loading. Please reload this page.
| https://github.com/github/codeql/security |
| Please reload this page | https://github.com/github/codeql/pull/8634 |
|
Insights
| https://github.com/github/codeql/pulse |
|
Code
| https://github.com/github/codeql |
|
Issues
| https://github.com/github/codeql/issues |
|
Pull requests
| https://github.com/github/codeql/pulls |
|
Discussions
| https://github.com/github/codeql/discussions |
|
Actions
| https://github.com/github/codeql/actions |
|
Projects
| https://github.com/github/codeql/projects |
|
Models
| https://github.com/github/codeql/models |
|
Security
| https://github.com/github/codeql/security |
|
Insights
| https://github.com/github/codeql/pulse |
| Sign up for GitHub
| https://github.com/signup?return_to=%2Fgithub%2Fcodeql%2Fissues%2Fnew%2Fchoose |
| terms of service | https://docs.github.com/terms |
| privacy statement | https://docs.github.com/privacy |
| Sign in | https://github.com/login?return_to=%2Fgithub%2Fcodeql%2Fissues%2Fnew%2Fchoose |
| Jump to bottom | https://github.com/github/codeql/pull/8634#issue-comment-box |
| yoff | https://github.com/yoff |
| github:main | https://github.com/github/codeql/tree/main |
| RasmusWL:promote-xxe | https://github.com/RasmusWL/codeql/tree/promote-xxe |
|
Python: Promote XXE and XML-bomb queries
| https://github.com/github/codeql/pull/8634#top |
| yoff | https://github.com/yoff |
| github:main | https://github.com/github/codeql/tree/main |
| RasmusWL:promote-xxe | https://github.com/RasmusWL/codeql/tree/promote-xxe |
|
Conversation
20
| https://github.com/github/codeql/pull/8634 |
|
Commits
54
| https://github.com/github/codeql/pull/8634/commits |
|
Checks
0
| https://github.com/github/codeql/pull/8634/checks |
|
Files changed
| https://github.com/github/codeql/pull/8634/files |
| Please reload this page | https://github.com/github/codeql/pull/8634 |
| https://github.co/hiddenchars |
| https://github.com/github/codeql/pull/{{ revealButtonHref }} |
|
| https://github.com/RasmusWL |
| RasmusWL | https://github.com/RasmusWL |
| Mar 31, 2022 | https://github.com/github/codeql/pull/8634#issue-1188376655 |
| Please reload this page | https://github.com/github/codeql/pull/8634 |
| Please reload this page | https://github.com/github/codeql/pull/8634 |
| RasmusWL | https://github.com/RasmusWL |
| March 31, 2022 09:52 | https://github.com/github/codeql/pull/8634#commits-pushed-65907c9 |
|
| https://github.com/RasmusWL |
| Python: Copy Xxe/XmlBomb queries from JS | https://github.com/github/codeql/pull/8634/commits/65907c97620e2824ffbd008db54a98d9ee1a1060 |
| 65907c9 | https://github.com/github/codeql/pull/8634/commits/65907c97620e2824ffbd008db54a98d9ee1a1060 |
|
| https://github.com/RasmusWL |
| Python: Adjust Xxe/XmlBomb for Python | https://github.com/github/codeql/pull/8634/commits/e45f9d69ccb44a2109518f3c8334e21f5c193a43 |
| e45f9d6 | https://github.com/github/codeql/pull/8634/commits/e45f9d69ccb44a2109518f3c8334e21f5c193a43 |
|
| https://github.com/RasmusWL |
| Python: Add simple test of Xxe/XmlBomb | https://github.com/github/codeql/pull/8634/commits/91795b857756a4912e6a280e4e53f65f4fbaf76a |
| 91795b8 | https://github.com/github/codeql/pull/8634/commits/91795b857756a4912e6a280e4e53f65f4fbaf76a |
|
| https://github.com/RasmusWL |
| Python: Adjust XXE PoC for newer lxml versions | https://github.com/github/codeql/pull/8634/commits/a1d88e39a77f4c16ca0e292ca5e6311828745b2e |
| a1d88e3 | https://github.com/github/codeql/pull/8634/commits/a1d88e39a77f4c16ca0e292ca5e6311828745b2e |
|
| https://github.com/RasmusWL |
| Python: XXE: Add example of exfiltrating data through dtd-retrival | https://github.com/github/codeql/pull/8634/commits/57b97804283545dbe986c019660ae5171ba8e7ed |
| 57b9780 | https://github.com/github/codeql/pull/8634/commits/57b97804283545dbe986c019660ae5171ba8e7ed |
|
| https://github.com/RasmusWL |
| Python: Add taint for StringIO and BytesIO | https://github.com/github/codeql/pull/8634/commits/769f5691d08dd8288e4eb6432e163b0a53c8ac21 |
| 769f569 | https://github.com/github/codeql/pull/8634/commits/769f5691d08dd8288e4eb6432e163b0a53c8ac21 |
|
| https://github.com/RasmusWL |
| Python: Delete XmlEntityInjection.ql | https://github.com/github/codeql/pull/8634/commits/c3653378671f7e8c39c20993f16f64224945bf97 |
| c365337 | https://github.com/github/codeql/pull/8634/commits/c3653378671f7e8c39c20993f16f64224945bf97 |
|
| https://github.com/RasmusWL |
| Python: Adjust XXE qhelp | https://github.com/github/codeql/pull/8634/commits/b00766b054d1b58a06dce48bd631a5b0eaacb7b7 |
| b00766b | https://github.com/github/codeql/pull/8634/commits/b00766b054d1b58a06dce48bd631a5b0eaacb7b7 |
|
| https://github.com/RasmusWL |
| Python: Adjust XmlBomb.qhelp from JS | https://github.com/github/codeql/pull/8634/commits/56b9c891d85636c543bf9529dd7b191908248be7 |
| 56b9c89 | https://github.com/github/codeql/pull/8634/commits/56b9c891d85636c543bf9529dd7b191908248be7 |
|
| https://github.com/RasmusWL |
| Python: Add PortSwigger link to Xxe.qhelp | https://github.com/github/codeql/pull/8634/commits/9caf4be21be7370a0317ae44205dfb35a5169073 |
| 9caf4be | https://github.com/github/codeql/pull/8634/commits/9caf4be21be7370a0317ae44205dfb35a5169073 |
|
| https://github.com/RasmusWL |
| Python: Promote XMLParsing concept | https://github.com/github/codeql/pull/8634/commits/e005a5c0ab7409ebb6fb0002cdc7ab11a1b54bd1 |
| e005a5c | https://github.com/github/codeql/pull/8634/commits/e005a5c0ab7409ebb6fb0002cdc7ab11a1b54bd1 |
|
| https://github.com/RasmusWL |
| Python: => XMLParsingVulnerabilityKind | https://github.com/github/codeql/pull/8634/commits/e45288e812a0cd0f87cb909768b60847ec5aa997 |
| e45288e | https://github.com/github/codeql/pull/8634/commits/e45288e812a0cd0f87cb909768b60847ec5aa997 |
|
| https://github.com/RasmusWL |
| Python: Promote XMLParsing concept test | https://github.com/github/codeql/pull/8634/commits/35ccba2ec10b2610969ac790d8ca8fa76a282ad9 |
| 35ccba2 | https://github.com/github/codeql/pull/8634/commits/35ccba2ec10b2610969ac790d8ca8fa76a282ad9 |
|
| https://github.com/RasmusWL |
| Python: Make XMLParsing a Decoding subclass | https://github.com/github/codeql/pull/8634/commits/1ea4bcc59f4ccbfe02e454ae3223a8fa34ac33e3 |
| 1ea4bcc | https://github.com/github/codeql/pull/8634/commits/1ea4bcc59f4ccbfe02e454ae3223a8fa34ac33e3 |
|
| https://github.com/RasmusWL |
| Python: Rename lxml XPath tests | https://github.com/github/codeql/pull/8634/commits/c4473c5f6506e6dcb8e6736f7d3ddd0acea022d4 |
| c4473c5 | https://github.com/github/codeql/pull/8634/commits/c4473c5f6506e6dcb8e6736f7d3ddd0acea022d4 |
|
| https://github.com/RasmusWL |
| Python: Handle XMLParser().close() for XPath | https://github.com/github/codeql/pull/8634/commits/3040adfd9bdc26a0c54ef04453a1c8b2420bb4c5 |
| 3040adf | https://github.com/github/codeql/pull/8634/commits/3040adfd9bdc26a0c54ef04453a1c8b2420bb4c5 |
|
| https://github.com/RasmusWL |
| Python: Promote lxml parsing modeling | https://github.com/github/codeql/pull/8634/commits/80b5cde3a2d3123029630450e41475f89253938c |
| 80b5cde | https://github.com/github/codeql/pull/8634/commits/80b5cde3a2d3123029630450e41475f89253938c |
|
| https://github.com/RasmusWL |
| Python: Promote xmltodict modeling | https://github.com/github/codeql/pull/8634/commits/7f5f7679f8f9f14db7fac551bfb6071c08c41767 |
| 7f5f767 | https://github.com/github/codeql/pull/8634/commits/7f5f7679f8f9f14db7fac551bfb6071c08c41767 |
|
| https://github.com/RasmusWL |
| Python: Promote xml.etree modeling | https://github.com/github/codeql/pull/8634/commits/64aa503cc3b6374744efbaa2d6f4c322d03a3faa |
| 64aa503 | https://github.com/github/codeql/pull/8634/commits/64aa503cc3b6374744efbaa2d6f4c322d03a3faa |
|
| https://github.com/RasmusWL |
| Python: Add some links in QLDocs | https://github.com/github/codeql/pull/8634/commits/a315aa84b2bdfad3cd3196336bbc1bc6fc658415 |
| a315aa8 | https://github.com/github/codeql/pull/8634/commits/a315aa84b2bdfad3cd3196336bbc1bc6fc658415 |
|
| https://github.com/RasmusWL |
| Python: Add note about parseid/XMLID | https://github.com/github/codeql/pull/8634/commits/6774085e7af76b7faa952d2b23cbc9232a57273d |
| 6774085 | https://github.com/github/codeql/pull/8634/commits/6774085e7af76b7faa952d2b23cbc9232a57273d |
|
| https://github.com/RasmusWL |
| Python: Model lxml.etree.XMLID | https://github.com/github/codeql/pull/8634/commits/12cbdcde284e4e8fbce7a02ae0f65cedeee7e4eb |
| 12cbdcd | https://github.com/github/codeql/pull/8634/commits/12cbdcde284e4e8fbce7a02ae0f65cedeee7e4eb |
|
| https://github.com/RasmusWL |
| Python: Model lxml.iterparse | https://github.com/github/codeql/pull/8634/commits/386ff5361415f17c248285300de71ca735e92f7a |
| 386ff53 | https://github.com/github/codeql/pull/8634/commits/386ff5361415f17c248285300de71ca735e92f7a |
|
| https://github.com/RasmusWL |
| Python: Model file access from XML parsing | https://github.com/github/codeql/pull/8634/commits/543454eff234ac2d403b932cb82b38309dea8002 |
| 543454e | https://github.com/github/codeql/pull/8634/commits/543454eff234ac2d403b932cb82b38309dea8002 |
|
| https://github.com/RasmusWL |
| Python: Add test showing misalignment of xml.etree modeling | https://github.com/github/codeql/pull/8634/commits/db43d043c4cdd59c65424f20fdcdc0a7d79a632c |
| db43d04 | https://github.com/github/codeql/pull/8634/commits/db43d043c4cdd59c65424f20fdcdc0a7d79a632c |
|
| https://github.com/RasmusWL |
| Python: Merge xml.etree.ElementTree models | https://github.com/github/codeql/pull/8634/commits/70b3eecdd506fcb2e17f3eb027e7b05073c257df |
| 70b3eec | https://github.com/github/codeql/pull/8634/commits/70b3eecdd506fcb2e17f3eb027e7b05073c257df |
|
| https://github.com/RasmusWL |
| Python: Align xml.etree.ElementTree modeling | https://github.com/github/codeql/pull/8634/commits/05bb0ef97688627eacd4b6ed247b84a707385ed5 |
| 05bb0ef | https://github.com/github/codeql/pull/8634/commits/05bb0ef97688627eacd4b6ed247b84a707385ed5 |
|
| https://github.com/RasmusWL |
| Python: Promote xml.sax and xml.dom.* modeling | https://github.com/github/codeql/pull/8634/commits/e11269715dc55e3509625489267601b736c324f1 |
| e112697 | https://github.com/github/codeql/pull/8634/commits/e11269715dc55e3509625489267601b736c324f1 |
|
| https://github.com/RasmusWL |
| Python: xml.sax.parse is not a method call | https://github.com/github/codeql/pull/8634/commits/1d7cec60ae09489618b7e561845b5a361c274583 |
| 1d7cec6 | https://github.com/github/codeql/pull/8634/commits/1d7cec60ae09489618b7e561845b5a361c274583 |
|
| https://github.com/RasmusWL |
| Python: Extend FileSystemAccess for xml.sax and xml.dom.* parsing | https://github.com/github/codeql/pull/8634/commits/b4c0065aeb160839129d25cc3ee1818564670d21 |
| b4c0065 | https://github.com/github/codeql/pull/8634/commits/b4c0065aeb160839129d25cc3ee1818564670d21 |
| https://github.com/RasmusWL |
| RasmusWL | https://github.com/RasmusWL |
|
Apr 5, 2022
| https://github.com/github/codeql/pull/8634#ref-pullrequest-1192955603 |
|
Python: Rewrite concepts to use extends ... instanceof ...
#8668
| https://github.com/github/codeql/pull/8668 |
| RasmusWL | https://github.com/RasmusWL |
| April 6, 2022 12:56 | https://github.com/github/codeql/pull/8634#commits-pushed-23637fd |
|
| https://github.com/RasmusWL |
| Merge branch 'main' into promote-xxe | https://github.com/github/codeql/pull/8634/commits/23637fd691ceb60f44abaf9abd63b157c948d610 |
| 23637fd | https://github.com/github/codeql/pull/8634/commits/23637fd691ceb60f44abaf9abd63b157c948d610 |
|
| https://github.com/RasmusWL |
| Python: Rename more XML classes to follow convention | https://github.com/github/codeql/pull/8634/commits/c784f15762b8ea2f749e1f3d92fe29d498b63de3 |
| c784f15 | https://github.com/github/codeql/pull/8634/commits/c784f15762b8ea2f749e1f3d92fe29d498b63de3 |
|
| https://github.com/RasmusWL |
| Python: Use new API::CallNode for XML constant check | https://github.com/github/codeql/pull/8634/commits/f2f0873d911dc9bb685fa708707e3f4c1de6fc9d |
| f2f0873 | https://github.com/github/codeql/pull/8634/commits/f2f0873d911dc9bb685fa708707e3f4c1de6fc9d |
| https://github.com/RasmusWL |
| RasmusWL | https://github.com/RasmusWL |
| Apr 6, 2022 | https://github.com/github/codeql/pull/8634#issuecomment-1090298819 |
| Please reload this page | https://github.com/github/codeql/pull/8634 |
|
| https://github.com/RasmusWL |
| Python: Change XmlBomb vulnerability kind | https://github.com/github/codeql/pull/8634/commits/7728b6cf1b750eadf462606dbc3ca0660e86417d |
| 7728b6c | https://github.com/github/codeql/pull/8634/commits/7728b6cf1b750eadf462606dbc3ca0660e86417d |
| https://github.com/RasmusWL |
| RasmusWL | https://github.com/RasmusWL |
| April 7, 2022 13:30 | https://github.com/github/codeql/pull/8634#event-6388606860 |
| RasmusWL | https://github.com/RasmusWL |
| April 7, 2022 15:37 | https://github.com/github/codeql/pull/8634#commits-pushed-405480c |
|
| https://github.com/RasmusWL |
| Python: Rename sink definitions for XXE/XML bomb | https://github.com/github/codeql/pull/8634/commits/405480c41045f943e025aa7d21a33b971b231cf2 |
| 405480c | https://github.com/github/codeql/pull/8634/commits/405480c41045f943e025aa7d21a33b971b231cf2 |
|
| https://github.com/RasmusWL |
| Python: Move last XXE/XML bomb out of experimental | https://github.com/github/codeql/pull/8634/commits/8191be9d7506bec7909a19f001276d2716d4f600 |
| 8191be9 | https://github.com/github/codeql/pull/8634/commits/8191be9d7506bec7909a19f001276d2716d4f600 |
|
| https://github.com/RasmusWL |
| Python: Fix SimpleXmlRpcServer.expected | https://github.com/github/codeql/pull/8634/commits/517444b5ff3067a178c57bdda5d523bd8c16316c |
| 517444b | https://github.com/github/codeql/pull/8634/commits/517444b5ff3067a178c57bdda5d523bd8c16316c |
|
| https://github.com/RasmusWL |
| Merge branch 'main' into promote-xxe | https://github.com/github/codeql/pull/8634/commits/bb6969a1753e18f997cfde4e055efe5cc92a9856 |
| bb6969a | https://github.com/github/codeql/pull/8634/commits/bb6969a1753e18f997cfde4e055efe5cc92a9856 |
| https://github.com/RasmusWL |
| RasmusWL | https://github.com/RasmusWL |
| April 20, 2022 11:48 | https://github.com/github/codeql/pull/8634#event-6462488658 |
| https://github.com/RasmusWL |
| RasmusWL | https://github.com/RasmusWL |
| Apr 22, 2022 | https://github.com/github/codeql/pull/8634#issuecomment-1106201158 |
| Please reload this page | https://github.com/github/codeql/pull/8634 |
| RasmusWL | https://github.com/RasmusWL |
| May 2, 2022 11:25 | https://github.com/github/codeql/pull/8634#commits-pushed-5f01fc2 |
|
| https://github.com/RasmusWL |
| Merge branch 'main' into promote-xxe | https://github.com/github/codeql/pull/8634/commits/5f01fc24e42967cecdc3eb27385234fcd51d6963 |
| 5f01fc2 | https://github.com/github/codeql/pull/8634/commits/5f01fc24e42967cecdc3eb27385234fcd51d6963 |
|
| https://github.com/RasmusWL |
| Python: Refactor SaxParserSetFeatureCall | https://github.com/github/codeql/pull/8634/commits/714465bf39d97e31aa6f0a7aa01c57e16f3c3078 |
| 714465b | https://github.com/github/codeql/pull/8634/commits/714465bf39d97e31aa6f0a7aa01c57e16f3c3078 |
| @erik-krogh | https://github.com/erik-krogh |
| https://github.com/github/codeql/pull/8693/files#diff-9627c1fb9a1cc77fb93e6b7e31af1a4fa908f2a60362cfb34377d24debb97398 | https://github.com/github/codeql/pull/8693/files#diff-9627c1fb9a1cc77fb93e6b7e31af1a4fa908f2a60362cfb34377d24debb97398 |
| https://github.com/yoff |
| yoff | https://github.com/yoff |
|
May 5, 2022
| https://github.com/github/codeql/pull/8634#pullrequestreview-963157395 |
|
View reviewed changes
| https://github.com/github/codeql/pull/8634/files/714465bf39d97e31aa6f0a7aa01c57e16f3c3078 |
| yoff | https://github.com/yoff |
| https://github.com/github/codeql/pull/8634#pullrequestreview-963157395 |
| Learn more | https://docs.github.com/articles/managing-disruptive-comments/#hiding-a-comment |
| Please reload this page | https://github.com/github/codeql/pull/8634 |
| python/ql/src/Security/CWE-776/XmlBomb.qhelp | https://github.com/github/codeql/pull/8634/files/714465bf39d97e31aa6f0a7aa01c57e16f3c3078#diff-07b39fdc090c761b185294759307cd9e7b9dbfe7aefda97d29d6027d7424e4e9 |
| Please reload this page | https://github.com/github/codeql/pull/8634 |
| python/ql/lib/change-notes/2022-03-29-add-taint-for-StringIO.md | https://github.com/github/codeql/pull/8634/files/714465bf39d97e31aa6f0a7aa01c57e16f3c3078#diff-453f60209bf9860dd9b7e884e3ce558327da95b1edcbb5f753ab729a3aa4c887 |
| Please reload this page | https://github.com/github/codeql/pull/8634 |
| python/ql/lib/semmle/python/frameworks/Lxml.qll | https://github.com/github/codeql/pull/8634/files/714465bf39d97e31aa6f0a7aa01c57e16f3c3078#diff-697c08d6bbeec88084fb0d09c2d3124a5fb8ca61821dfdc66caa40b862819fe3 |
| yoff | https://github.com/yoff |
| May 5, 2022 | https://github.com/github/codeql/pull/8634#discussion_r865968608 |
| Learn more | https://docs.github.com/articles/managing-disruptive-comments/#hiding-a-comment |
| Please reload this page | https://github.com/github/codeql/pull/8634 |
| https://github.com/RasmusWL |
| RasmusWL | https://github.com/RasmusWL |
| May 9, 2022 | https://github.com/github/codeql/pull/8634#issuecomment-1120822733 |
| https://github.com/github/codeql/blob/714465bf39d97e31aa6f0a7aa01c57e16f3c3078/python/PoCs/XmlParsing/PoC.py | https://github.com/github/codeql/blob/714465bf39d97e31aa6f0a7aa01c57e16f3c3078/python/PoCs/XmlParsing/PoC.py |
| Please reload this page | https://github.com/github/codeql/pull/8634 |
| RasmusWL | https://github.com/RasmusWL |
| May 9, 2022 10:53 | https://github.com/github/codeql/pull/8634#commits-pushed-f5854f3 |
|
| https://github.com/RasmusWL |
|
| https://github.com/yoff |
| Python: Apply suggestions from code review | https://github.com/github/codeql/pull/8634/commits/f5854f33da4a51c39e4a6bccb778393d92e29efe |
| f5854f3 | https://github.com/github/codeql/pull/8634/commits/f5854f33da4a51c39e4a6bccb778393d92e29efe |
|
| https://github.com/RasmusWL |
| Python: Slight refactor of LxmlParsing | https://github.com/github/codeql/pull/8634/commits/f22bd039f3014cb00e2f6211b686f5b2fc9198fd |
| f22bd03 | https://github.com/github/codeql/pull/8634/commits/f22bd039f3014cb00e2f6211b686f5b2fc9198fd |
| https://github.com/apps/github-advanced-security |
| github-advanced-security | https://github.com/apps/github-advanced-security |
|
May 9, 2022
| https://github.com/github/codeql/pull/8634#pullrequestreview-965811330 |
|
View reviewed changes
| https://github.com/github/codeql/pull/8634/files/f5854f33da4a51c39e4a6bccb778393d92e29efe |
| github-advanced-security | https://github.com/apps/github-advanced-security |
| https://github.com/github/codeql/pull/8634#pullrequestreview-965811330 |
| Learn more | https://docs.github.com/articles/managing-disruptive-comments/#hiding-a-comment |
| Please reload this page | https://github.com/github/codeql/pull/8634 |
| python/ql/lib/semmle/python/frameworks/Stdlib.qll | https://github.com/github/codeql/pull/8634/files/f5854f33da4a51c39e4a6bccb778393d92e29efe#diff-cac9a82bbea79b64358a082adcd1d176aa565091e6c6391c3b61cbb1bf784971 |
| Please reload this page | https://github.com/github/codeql/pull/8634 |
| python/ql/lib/semmle/python/frameworks/Stdlib.qll | https://github.com/github/codeql/pull/8634/files/f5854f33da4a51c39e4a6bccb778393d92e29efe#diff-cac9a82bbea79b64358a082adcd1d176aa565091e6c6391c3b61cbb1bf784971 |
| python/ql/lib/semmle/python/frameworks/Stdlib.qll | https://github.com/github/codeql/pull/8634/files/f5854f33da4a51c39e4a6bccb778393d92e29efe#diff-cac9a82bbea79b64358a082adcd1d176aa565091e6c6391c3b61cbb1bf784971 |
| python/ql/test/experimental/meta/ConceptsTest.qll | https://github.com/github/codeql/pull/8634/files/f5854f33da4a51c39e4a6bccb778393d92e29efe#diff-3b8283245699453d7bcadeac6ce20139bacb391c1453a5ddff95995e75eb51c0 |
| Please reload this page | https://github.com/github/codeql/pull/8634 |
| python/ql/lib/semmle/python/frameworks/Stdlib.qll | https://github.com/github/codeql/pull/8634/files/f5854f33da4a51c39e4a6bccb778393d92e29efe#diff-cac9a82bbea79b64358a082adcd1d176aa565091e6c6391c3b61cbb1bf784971 |
| Please reload this page | https://github.com/github/codeql/pull/8634 |
| RasmusWL | https://github.com/RasmusWL |
| May 9, 2022 11:00 | https://github.com/github/codeql/pull/8634#commits-pushed-3634922 |
|
| https://github.com/RasmusWL |
| Python: Fix casing of XMLDomParsing | https://github.com/github/codeql/pull/8634/commits/36349222a9561c6996fbd6f2e30ab8580313e5ac |
| 3634922 | https://github.com/github/codeql/pull/8634/commits/36349222a9561c6996fbd6f2e30ab8580313e5ac |
|
| https://github.com/RasmusWL |
| Python: Fix singleton set | https://github.com/github/codeql/pull/8634/commits/de05b108faaa469952bf8d83cfa0f2b5d6e086b4 |
| de05b10 | https://github.com/github/codeql/pull/8634/commits/de05b108faaa469952bf8d83cfa0f2b5d6e086b4 |
| https://github.com/RasmusWL |
| RasmusWL | https://github.com/RasmusWL |
| May 9, 2022 | https://github.com/github/codeql/pull/8634#issuecomment-1120839368 |
| Please reload this page | https://github.com/github/codeql/pull/8634 |
| https://github.com/RasmusWL |
| RasmusWL | https://github.com/RasmusWL |
| yoff | https://github.com/yoff |
| May 9, 2022 09:52 | https://github.com/github/codeql/pull/8634#event-6571759631 |
| https://github.com/yoff |
| yoff | https://github.com/yoff |
|
May 9, 2022
| https://github.com/github/codeql/pull/8634#pullrequestreview-966023200 |
|
View reviewed changes
| https://github.com/github/codeql/pull/8634/files/de05b108faaa469952bf8d83cfa0f2b5d6e086b4 |
| yoff | https://github.com/yoff |
| https://github.com/github/codeql/pull/8634#pullrequestreview-966023200 |
| Learn more | https://docs.github.com/articles/managing-disruptive-comments/#hiding-a-comment |
| Please reload this page | https://github.com/github/codeql/pull/8634 |
| python/ql/lib/semmle/python/frameworks/Stdlib.qll | https://github.com/github/codeql/pull/8634/files/de05b108faaa469952bf8d83cfa0f2b5d6e086b4#diff-cac9a82bbea79b64358a082adcd1d176aa565091e6c6391c3b61cbb1bf784971 |
| Please reload this page | https://github.com/github/codeql/pull/8634 |
|
| https://github.com/RasmusWL |
|
| https://github.com/yoff |
| Python: Apply suggestions from code review | https://github.com/github/codeql/pull/8634/commits/4a6789182d4d4d18526e05d05cf3028c3a59b92c |
| 4a67891 | https://github.com/github/codeql/pull/8634/commits/4a6789182d4d4d18526e05d05cf3028c3a59b92c |
| https://github.com/RasmusWL |
| RasmusWL | https://github.com/RasmusWL |
| yoff | https://github.com/yoff |
| May 9, 2022 14:37 | https://github.com/github/codeql/pull/8634#event-6573784747 |
| https://github.com/yoff |
| yoff | https://github.com/yoff |
|
May 9, 2022
| https://github.com/github/codeql/pull/8634#pullrequestreview-966758612 |
|
View reviewed changes
| https://github.com/github/codeql/pull/8634/files/4a6789182d4d4d18526e05d05cf3028c3a59b92c |
| yoff | https://github.com/yoff |
| https://github.com/github/codeql/pull/8634#pullrequestreview-966758612 |
| Learn more | https://docs.github.com/articles/managing-disruptive-comments/#hiding-a-comment |
| Please reload this page | https://github.com/github/codeql/pull/8634 |
| https://github.com/yoff |
| yoff | https://github.com/yoff |
| b6605bc | https://github.com/github/codeql/commit/b6605bc33098657f6ec81da8e1304839c4ae25ad |
| May 9, 2022 | https://github.com/github/codeql/pull/8634#event-6575871569 |
| https://github.com/RasmusWL |
| RasmusWL | https://github.com/RasmusWL |
| May 10, 2022 08:46 | https://github.com/github/codeql/pull/8634#event-6580002341 |
| Sign up for free | https://github.com/join?source=comment-repo |
| Sign in to comment | https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fgithub%2Fcodeql%2Fpull%2F8634 |
|
| https://github.com/yoff |
|
yoff
| https://github.com/yoff |
|
| https://github.com/github/codeql/pull/8634/files/4a6789182d4d4d18526e05d05cf3028c3a59b92c |
|
documentation
| https://github.com/github/codeql/issues?q=state%3Aopen%20label%3Adocumentation |
|
Python
| https://github.com/github/codeql/issues?q=state%3Aopen%20label%3APython |
| Please reload this page | https://github.com/github/codeql/pull/8634 |
|
| https://github.com/RasmusWL |
|
| https://github.com/yoff |
|
| https://github.com |
| Terms | https://docs.github.com/site-policy/github-terms/github-terms-of-service |
| Privacy | https://docs.github.com/site-policy/privacy-policies/github-privacy-statement |
| Security | https://github.com/security |
| Status | https://www.githubstatus.com/ |
| Community | https://github.community/ |
| Docs | https://docs.github.com/ |
| Contact | https://support.github.com?tags=dotcom-footer |