Skip to content

Commit 2952c0d

Browse files
authored
Merge pull request #19507 from michaelnebel/removehardcodedpassword
Exclude some queries from query suites by lowering their precision.
2 parents 789e881 + dabeddb commit 2952c0d

File tree

41 files changed

+50
-36
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

41 files changed

+50
-36
lines changed

csharp/ql/integration-tests/posix/query-suite/csharp-security-and-quality.qls.expected

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -38,7 +38,6 @@ ql/csharp/ql/src/Concurrency/SynchSetUnsynchGet.ql
3838
ql/csharp/ql/src/Concurrency/UnsafeLazyInitialization.ql
3939
ql/csharp/ql/src/Concurrency/UnsynchronizedStaticAccess.ql
4040
ql/csharp/ql/src/Configuration/EmptyPasswordInConfigurationFile.ql
41-
ql/csharp/ql/src/Configuration/PasswordInConfigurationFile.ql
4241
ql/csharp/ql/src/Dead Code/DeadStoreOfLocal.ql
4342
ql/csharp/ql/src/Diagnostics/CompilerError.ql
4443
ql/csharp/ql/src/Diagnostics/CompilerMessage.ql
@@ -146,8 +145,6 @@ ql/csharp/ql/src/Security Features/CWE-639/InsecureDirectObjectReference.ql
146145
ql/csharp/ql/src/Security Features/CWE-643/XPathInjection.ql
147146
ql/csharp/ql/src/Security Features/CWE-730/ReDoS.ql
148147
ql/csharp/ql/src/Security Features/CWE-730/RegexInjection.ql
149-
ql/csharp/ql/src/Security Features/CWE-798/HardcodedConnectionString.ql
150-
ql/csharp/ql/src/Security Features/CWE-798/HardcodedCredentials.ql
151148
ql/csharp/ql/src/Security Features/CWE-807/ConditionalBypass.ql
152149
ql/csharp/ql/src/Security Features/CookieWithOverlyBroadDomain.ql
153150
ql/csharp/ql/src/Security Features/CookieWithOverlyBroadPath.ql

csharp/ql/integration-tests/posix/query-suite/csharp-security-extended.qls.expected

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,4 @@
11
ql/csharp/ql/src/Configuration/EmptyPasswordInConfigurationFile.ql
2-
ql/csharp/ql/src/Configuration/PasswordInConfigurationFile.ql
32
ql/csharp/ql/src/Diagnostics/CompilerError.ql
43
ql/csharp/ql/src/Diagnostics/CompilerMessage.ql
54
ql/csharp/ql/src/Diagnostics/DiagnosticExtractionErrors.ql
@@ -49,8 +48,6 @@ ql/csharp/ql/src/Security Features/CWE-639/InsecureDirectObjectReference.ql
4948
ql/csharp/ql/src/Security Features/CWE-643/XPathInjection.ql
5049
ql/csharp/ql/src/Security Features/CWE-730/ReDoS.ql
5150
ql/csharp/ql/src/Security Features/CWE-730/RegexInjection.ql
52-
ql/csharp/ql/src/Security Features/CWE-798/HardcodedConnectionString.ql
53-
ql/csharp/ql/src/Security Features/CWE-798/HardcodedCredentials.ql
5451
ql/csharp/ql/src/Security Features/CWE-807/ConditionalBypass.ql
5552
ql/csharp/ql/src/Security Features/CookieWithOverlyBroadDomain.ql
5653
ql/csharp/ql/src/Security Features/CookieWithOverlyBroadPath.ql

csharp/ql/integration-tests/posix/query-suite/not_included_in_qls.expected

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -26,6 +26,7 @@ ql/csharp/ql/src/Bad Practices/Naming Conventions/DefaultControlNames.ql
2626
ql/csharp/ql/src/Bad Practices/Naming Conventions/VariableNameTooShort.ql
2727
ql/csharp/ql/src/Bad Practices/UseOfHtmlInputHidden.ql
2828
ql/csharp/ql/src/Bad Practices/UseOfSystemOutputStream.ql
29+
ql/csharp/ql/src/Configuration/PasswordInConfigurationFile.ql
2930
ql/csharp/ql/src/Dead Code/DeadRefTypes.ql
3031
ql/csharp/ql/src/Dead Code/NonAssignedFields.ql
3132
ql/csharp/ql/src/Dead Code/UnusedField.ql
@@ -89,6 +90,8 @@ ql/csharp/ql/src/Security Features/CWE-321/HardcodedSymmetricEncryptionKey.ql
8990
ql/csharp/ql/src/Security Features/CWE-327/DontInstallRootCert.ql
9091
ql/csharp/ql/src/Security Features/CWE-502/UnsafeDeserialization.ql
9192
ql/csharp/ql/src/Security Features/CWE-611/UseXmlSecureResolver.ql
93+
ql/csharp/ql/src/Security Features/CWE-798/HardcodedConnectionString.ql
94+
ql/csharp/ql/src/Security Features/CWE-798/HardcodedCredentials.ql
9295
ql/csharp/ql/src/Security Features/CWE-838/InappropriateEncoding.ql
9396
ql/csharp/ql/src/Useless code/PointlessForwardingMethod.ql
9497
ql/csharp/ql/src/definitions.ql

csharp/ql/src/Configuration/PasswordInConfigurationFile.ql

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@
44
* @kind problem
55
* @problem.severity warning
66
* @security-severity 7.5
7-
* @precision medium
7+
* @precision low
88
* @id cs/password-in-configuration
99
* @tags security
1010
* external/cwe/cwe-013

csharp/ql/src/Security Features/CWE-798/HardcodedConnectionString.ql

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@
44
* @kind path-problem
55
* @problem.severity error
66
* @security-severity 9.8
7-
* @precision medium
7+
* @precision low
88
* @id cs/hardcoded-connection-string-credentials
99
* @tags security
1010
* external/cwe/cwe-259

csharp/ql/src/Security Features/CWE-798/HardcodedCredentials.ql

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@
44
* @kind path-problem
55
* @problem.severity error
66
* @security-severity 9.8
7-
* @precision medium
7+
* @precision low
88
* @id cs/hardcoded-credentials
99
* @tags security
1010
* external/cwe/cwe-259
Lines changed: 4 additions & 0 deletions

go/ql/integration-tests/query-suite/go-security-and-quality.qls.expected

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -50,6 +50,5 @@ ql/go/ql/src/Security/CWE-640/EmailInjection.ql
5050
ql/go/ql/src/Security/CWE-643/XPathInjection.ql
5151
ql/go/ql/src/Security/CWE-681/IncorrectIntegerConversionQuery.ql
5252
ql/go/ql/src/Security/CWE-770/UncontrolledAllocationSize.ql
53-
ql/go/ql/src/Security/CWE-798/HardcodedCredentials.ql
5453
ql/go/ql/src/Security/CWE-918/RequestForgery.ql
5554
ql/go/ql/src/Summary/LinesOfCode.ql

go/ql/integration-tests/query-suite/go-security-extended.qls.expected

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -28,6 +28,5 @@ ql/go/ql/src/Security/CWE-640/EmailInjection.ql
2828
ql/go/ql/src/Security/CWE-643/XPathInjection.ql
2929
ql/go/ql/src/Security/CWE-681/IncorrectIntegerConversionQuery.ql
3030
ql/go/ql/src/Security/CWE-770/UncontrolledAllocationSize.ql
31-
ql/go/ql/src/Security/CWE-798/HardcodedCredentials.ql
3231
ql/go/ql/src/Security/CWE-918/RequestForgery.ql
3332
ql/go/ql/src/Summary/LinesOfCode.ql

go/ql/integration-tests/query-suite/not_included_in_qls.expected

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,7 @@ ql/go/ql/src/Security/CWE-020/UntrustedDataToExternalAPI.ql
66
ql/go/ql/src/Security/CWE-020/UntrustedDataToUnknownExternalAPI.ql
77
ql/go/ql/src/Security/CWE-078/StoredCommand.ql
88
ql/go/ql/src/Security/CWE-079/StoredXss.ql
9+
ql/go/ql/src/Security/CWE-798/HardcodedCredentials.ql
910
ql/go/ql/src/definitions.ql
1011
ql/go/ql/src/experimental/CWE-090/LDAPInjection.ql
1112
ql/go/ql/src/experimental/CWE-1004/CookieWithoutHttpOnly.ql

go/ql/src/Security/CWE-798/HardcodedCredentials.ql

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@
55
* @kind problem
66
* @problem.severity warning
77
* @security-severity 9.8
8-
* @precision medium
8+
* @precision low
99
* @id go/hardcoded-credentials
1010
* @tags security
1111
* external/cwe/cwe-259
Lines changed: 4 additions & 0 deletions

java/ql/integration-tests/java/query-suite/java-security-and-quality.qls.expected

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -196,7 +196,6 @@ ql/java/ql/src/Security/CWE/CWE-730/RegexInjection.ql
196196
ql/java/ql/src/Security/CWE/CWE-732/ReadingFromWorldWritableFile.ql
197197
ql/java/ql/src/Security/CWE/CWE-749/UnsafeAndroidAccess.ql
198198
ql/java/ql/src/Security/CWE/CWE-780/RsaWithoutOaep.ql
199-
ql/java/ql/src/Security/CWE/CWE-798/HardcodedCredentialsApiCall.ql
200199
ql/java/ql/src/Security/CWE/CWE-807/ConditionalBypass.ql
201200
ql/java/ql/src/Security/CWE/CWE-807/TaintedPermissionsCheck.ql
202201
ql/java/ql/src/Security/CWE/CWE-829/InsecureDependencyResolution.ql

java/ql/integration-tests/java/query-suite/java-security-extended.qls.expected

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -99,7 +99,6 @@ ql/java/ql/src/Security/CWE/CWE-730/RegexInjection.ql
9999
ql/java/ql/src/Security/CWE/CWE-732/ReadingFromWorldWritableFile.ql
100100
ql/java/ql/src/Security/CWE/CWE-749/UnsafeAndroidAccess.ql
101101
ql/java/ql/src/Security/CWE/CWE-780/RsaWithoutOaep.ql
102-
ql/java/ql/src/Security/CWE/CWE-798/HardcodedCredentialsApiCall.ql
103102
ql/java/ql/src/Security/CWE/CWE-807/ConditionalBypass.ql
104103
ql/java/ql/src/Security/CWE/CWE-807/TaintedPermissionsCheck.ql
105104
ql/java/ql/src/Security/CWE/CWE-829/InsecureDependencyResolution.ql

java/ql/integration-tests/java/query-suite/not_included_in_qls.expected

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -158,6 +158,7 @@ ql/java/ql/src/Security/CWE/CWE-312/CleartextStorageClass.ql
158158
ql/java/ql/src/Security/CWE/CWE-319/HttpsUrls.ql
159159
ql/java/ql/src/Security/CWE/CWE-319/UseSSL.ql
160160
ql/java/ql/src/Security/CWE/CWE-319/UseSSLSocketFactories.ql
161+
ql/java/ql/src/Security/CWE/CWE-798/HardcodedCredentialsApiCall.ql
161162
ql/java/ql/src/Security/CWE/CWE-798/HardcodedCredentialsComparison.ql
162163
ql/java/ql/src/Security/CWE/CWE-798/HardcodedCredentialsSourceCall.ql
163164
ql/java/ql/src/Security/CWE/CWE-798/HardcodedPasswordField.ql

java/ql/src/Security/CWE/CWE-798/HardcodedCredentialsApiCall.ql

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@
44
* @kind path-problem
55
* @problem.severity error
66
* @security-severity 9.8
7-
* @precision medium
7+
* @precision low
88
* @id java/hardcoded-credential-api-call
99
* @tags security
1010
* external/cwe/cwe-798
Lines changed: 4 additions & 0 deletions

javascript/ql/integration-tests/query-suite/javascript-code-scanning.qls.expected

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -75,7 +75,6 @@ ql/javascript/ql/src/Security/CWE-754/UnvalidatedDynamicMethodCall.ql
7575
ql/javascript/ql/src/Security/CWE-770/MissingRateLimiting.ql
7676
ql/javascript/ql/src/Security/CWE-770/ResourceExhaustion.ql
7777
ql/javascript/ql/src/Security/CWE-776/XmlBomb.ql
78-
ql/javascript/ql/src/Security/CWE-798/HardcodedCredentials.ql
7978
ql/javascript/ql/src/Security/CWE-829/InsecureDownload.ql
8079
ql/javascript/ql/src/Security/CWE-830/FunctionalityFromUntrustedDomain.ql
8180
ql/javascript/ql/src/Security/CWE-830/FunctionalityFromUntrustedSource.ql

javascript/ql/integration-tests/query-suite/javascript-security-and-quality.qls.expected

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -144,7 +144,6 @@ ql/javascript/ql/src/Security/CWE-312/ActionsArtifactLeak.ql
144144
ql/javascript/ql/src/Security/CWE-312/BuildArtifactLeak.ql
145145
ql/javascript/ql/src/Security/CWE-312/CleartextLogging.ql
146146
ql/javascript/ql/src/Security/CWE-312/CleartextStorage.ql
147-
ql/javascript/ql/src/Security/CWE-313/PasswordInConfigurationFile.ql
148147
ql/javascript/ql/src/Security/CWE-326/InsufficientKeySize.ql
149148
ql/javascript/ql/src/Security/CWE-327/BadRandomness.ql
150149
ql/javascript/ql/src/Security/CWE-327/BrokenCryptoAlgorithm.ql
@@ -173,7 +172,6 @@ ql/javascript/ql/src/Security/CWE-754/UnvalidatedDynamicMethodCall.ql
173172
ql/javascript/ql/src/Security/CWE-770/MissingRateLimiting.ql
174173
ql/javascript/ql/src/Security/CWE-770/ResourceExhaustion.ql
175174
ql/javascript/ql/src/Security/CWE-776/XmlBomb.ql
176-
ql/javascript/ql/src/Security/CWE-798/HardcodedCredentials.ql
177175
ql/javascript/ql/src/Security/CWE-807/ConditionalBypass.ql
178176
ql/javascript/ql/src/Security/CWE-829/InsecureDownload.ql
179177
ql/javascript/ql/src/Security/CWE-830/FunctionalityFromUntrustedDomain.ql

javascript/ql/integration-tests/query-suite/javascript-security-extended.qls.expected

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -59,7 +59,6 @@ ql/javascript/ql/src/Security/CWE-312/ActionsArtifactLeak.ql
5959
ql/javascript/ql/src/Security/CWE-312/BuildArtifactLeak.ql
6060
ql/javascript/ql/src/Security/CWE-312/CleartextLogging.ql
6161
ql/javascript/ql/src/Security/CWE-312/CleartextStorage.ql
62-
ql/javascript/ql/src/Security/CWE-313/PasswordInConfigurationFile.ql
6362
ql/javascript/ql/src/Security/CWE-326/InsufficientKeySize.ql
6463
ql/javascript/ql/src/Security/CWE-327/BadRandomness.ql
6564
ql/javascript/ql/src/Security/CWE-327/BrokenCryptoAlgorithm.ql
@@ -88,7 +87,6 @@ ql/javascript/ql/src/Security/CWE-754/UnvalidatedDynamicMethodCall.ql
8887
ql/javascript/ql/src/Security/CWE-770/MissingRateLimiting.ql
8988
ql/javascript/ql/src/Security/CWE-770/ResourceExhaustion.ql
9089
ql/javascript/ql/src/Security/CWE-776/XmlBomb.ql
91-
ql/javascript/ql/src/Security/CWE-798/HardcodedCredentials.ql
9290
ql/javascript/ql/src/Security/CWE-807/ConditionalBypass.ql
9391
ql/javascript/ql/src/Security/CWE-829/InsecureDownload.ql
9492
ql/javascript/ql/src/Security/CWE-830/FunctionalityFromUntrustedDomain.ql

javascript/ql/integration-tests/query-suite/not_included_in_qls.expected

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -53,7 +53,9 @@ ql/javascript/ql/src/RegExp/BackspaceEscape.ql
5353
ql/javascript/ql/src/RegExp/MalformedRegExp.ql
5454
ql/javascript/ql/src/Security/CWE-020/ExternalAPIsUsedWithUntrustedData.ql
5555
ql/javascript/ql/src/Security/CWE-020/UntrustedDataToExternalAPI.ql
56+
ql/javascript/ql/src/Security/CWE-313/PasswordInConfigurationFile.ql
5657
ql/javascript/ql/src/Security/CWE-451/MissingXFrameOptions.ql
58+
ql/javascript/ql/src/Security/CWE-798/HardcodedCredentials.ql
5759
ql/javascript/ql/src/Security/CWE-807/DifferentKindsComparisonBypass.ql
5860
ql/javascript/ql/src/Security/trest/test.ql
5961
ql/javascript/ql/src/Statements/EphemeralLoop.ql

javascript/ql/src/Security/CWE-313/PasswordInConfigurationFile.ql

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@
44
* @kind problem
55
* @problem.severity warning
66
* @security-severity 7.5
7-
* @precision medium
7+
* @precision low
88
* @id js/password-in-configuration-file
99
* @tags security
1010
* external/cwe/cwe-256

javascript/ql/src/Security/CWE-798/HardcodedCredentials.ql

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@
55
* @kind path-problem
66
* @problem.severity warning
77
* @security-severity 9.8
8-
* @precision high
8+
* @precision low
99
* @id js/hardcoded-credentials
1010
* @tags security
1111
* external/cwe/cwe-259
Lines changed: 4 additions & 0 deletions

python/ql/integration-tests/query-suite/not_included_in_qls.expected

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -58,6 +58,7 @@ ql/python/ql/src/Metrics/NumberOfStatements.ql
5858
ql/python/ql/src/Metrics/TransitiveImports.ql
5959
ql/python/ql/src/Security/CWE-020-ExternalAPIs/ExternalAPIsUsedWithUntrustedData.ql
6060
ql/python/ql/src/Security/CWE-020-ExternalAPIs/UntrustedDataToExternalAPI.ql
61+
ql/python/ql/src/Security/CWE-798/HardcodedCredentials.ql
6162
ql/python/ql/src/Statements/AssertLiteralConstant.ql
6263
ql/python/ql/src/Statements/C_StyleParentheses.ql
6364
ql/python/ql/src/Statements/DocStrings.ql

python/ql/integration-tests/query-suite/python-security-and-quality.qls.expected

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -133,7 +133,6 @@ ql/python/ql/src/Security/CWE-730/ReDoS.ql
133133
ql/python/ql/src/Security/CWE-730/RegexInjection.ql
134134
ql/python/ql/src/Security/CWE-732/WeakFilePermissions.ql
135135
ql/python/ql/src/Security/CWE-776/XmlBomb.ql
136-
ql/python/ql/src/Security/CWE-798/HardcodedCredentials.ql
137136
ql/python/ql/src/Security/CWE-918/FullServerSideRequestForgery.ql
138137
ql/python/ql/src/Security/CWE-918/PartialServerSideRequestForgery.ql
139138
ql/python/ql/src/Security/CWE-943/NoSqlInjection.ql

python/ql/integration-tests/query-suite/python-security-extended.qls.expected

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -43,7 +43,6 @@ ql/python/ql/src/Security/CWE-730/ReDoS.ql
4343
ql/python/ql/src/Security/CWE-730/RegexInjection.ql
4444
ql/python/ql/src/Security/CWE-732/WeakFilePermissions.ql
4545
ql/python/ql/src/Security/CWE-776/XmlBomb.ql
46-
ql/python/ql/src/Security/CWE-798/HardcodedCredentials.ql
4746
ql/python/ql/src/Security/CWE-918/FullServerSideRequestForgery.ql
4847
ql/python/ql/src/Security/CWE-918/PartialServerSideRequestForgery.ql
4948
ql/python/ql/src/Security/CWE-943/NoSqlInjection.ql

python/ql/src/Security/CWE-798/HardcodedCredentials.ql

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@
44
* @kind path-problem
55
* @problem.severity error
66
* @security-severity 9.8
7-
* @precision medium
7+
* @precision low
88
* @id py/hardcoded-credentials
99
* @tags security
1010
* external/cwe/cwe-259
Lines changed: 4 additions & 0 deletions

ruby/ql/integration-tests/query-suite/not_included_in_qls.expected

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -30,6 +30,7 @@ ql/ruby/ql/src/queries/metrics/FLinesOfCode.ql
3030
ql/ruby/ql/src/queries/metrics/FLinesOfComments.ql
3131
ql/ruby/ql/src/queries/modeling/GenerateModel.ql
3232
ql/ruby/ql/src/queries/security/cwe-732/WeakFilePermissions.ql
33+
ql/ruby/ql/src/queries/security/cwe-798/HardcodedCredentials.ql
3334
ql/ruby/ql/src/queries/variables/UnusedParameter.ql
3435
ql/ruby/ql/src/utils/modeleditor/ApplicationModeEndpoints.ql
3536
ql/ruby/ql/src/utils/modeleditor/FrameworkModeAccessPaths.ql

ruby/ql/integration-tests/query-suite/ruby-security-and-quality.qls.expected

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,6 @@ ql/ruby/ql/src/queries/security/cwe-598/SensitiveGetQuery.ql
4141
ql/ruby/ql/src/queries/security/cwe-601/UrlRedirect.ql
4242
ql/ruby/ql/src/queries/security/cwe-611/Xxe.ql
4343
ql/ruby/ql/src/queries/security/cwe-732/WeakCookieConfiguration.ql
44-
ql/ruby/ql/src/queries/security/cwe-798/HardcodedCredentials.ql
4544
ql/ruby/ql/src/queries/security/cwe-829/InsecureDownload.ql
4645
ql/ruby/ql/src/queries/security/cwe-912/HttpToFileAccess.ql
4746
ql/ruby/ql/src/queries/security/cwe-915/MassAssignment.ql

ruby/ql/integration-tests/query-suite/ruby-security-extended.qls.expected

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -40,7 +40,6 @@ ql/ruby/ql/src/queries/security/cwe-598/SensitiveGetQuery.ql
4040
ql/ruby/ql/src/queries/security/cwe-601/UrlRedirect.ql
4141
ql/ruby/ql/src/queries/security/cwe-611/Xxe.ql
4242
ql/ruby/ql/src/queries/security/cwe-732/WeakCookieConfiguration.ql
43-
ql/ruby/ql/src/queries/security/cwe-798/HardcodedCredentials.ql
4443
ql/ruby/ql/src/queries/security/cwe-829/InsecureDownload.ql
4544
ql/ruby/ql/src/queries/security/cwe-912/HttpToFileAccess.ql
4645
ql/ruby/ql/src/queries/security/cwe-915/MassAssignment.ql
Lines changed: 4 additions & 0 deletions

ruby/ql/src/queries/security/cwe-798/HardcodedCredentials.ql

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@
44
* @kind path-problem
55
* @problem.severity error
66
* @security-severity 9.8
7-
* @precision medium
7+
* @precision low
88
* @id rb/hardcoded-credentials
99
* @tags security
1010
* external/cwe/cwe-259

swift/ql/integration-tests/posix/query-suite/not_included_in_qls.expected

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,7 @@
11
ql/swift/ql/src/AlertSuppression.ql
22
ql/swift/ql/src/experimental/Security/CWE-022/UnsafeUnpack.ql
3+
ql/swift/ql/src/queries/Security/CWE-259/ConstantPassword.ql
4+
ql/swift/ql/src/queries/Security/CWE-321/HardcodedEncryptionKey.ql
35
ql/swift/ql/src/queries/Summary/FlowSources.ql
46
ql/swift/ql/src/queries/Summary/QuerySinks.ql
57
ql/swift/ql/src/queries/Summary/RegexEvals.ql

swift/ql/integration-tests/posix/query-suite/swift-code-scanning.qls.expected

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,12 +14,10 @@ ql/swift/ql/src/queries/Security/CWE-1204/StaticInitializationVector.ql
1414
ql/swift/ql/src/queries/Security/CWE-1333/ReDoS.ql
1515
ql/swift/ql/src/queries/Security/CWE-134/UncontrolledFormatString.ql
1616
ql/swift/ql/src/queries/Security/CWE-135/StringLengthConflation.ql
17-
ql/swift/ql/src/queries/Security/CWE-259/ConstantPassword.ql
1817
ql/swift/ql/src/queries/Security/CWE-311/CleartextStorageDatabase.ql
1918
ql/swift/ql/src/queries/Security/CWE-311/CleartextTransmission.ql
2019
ql/swift/ql/src/queries/Security/CWE-312/CleartextLogging.ql
2120
ql/swift/ql/src/queries/Security/CWE-312/CleartextStoragePreferences.ql
22-
ql/swift/ql/src/queries/Security/CWE-321/HardcodedEncryptionKey.ql
2321
ql/swift/ql/src/queries/Security/CWE-327/ECBEncryption.ql
2422
ql/swift/ql/src/queries/Security/CWE-328/WeakPasswordHashing.ql
2523
ql/swift/ql/src/queries/Security/CWE-328/WeakSensitiveDataHashing.ql

swift/ql/integration-tests/posix/query-suite/swift-security-and-quality.qls.expected

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -15,12 +15,10 @@ ql/swift/ql/src/queries/Security/CWE-1204/StaticInitializationVector.ql
1515
ql/swift/ql/src/queries/Security/CWE-1333/ReDoS.ql
1616
ql/swift/ql/src/queries/Security/CWE-134/UncontrolledFormatString.ql
1717
ql/swift/ql/src/queries/Security/CWE-135/StringLengthConflation.ql
18-
ql/swift/ql/src/queries/Security/CWE-259/ConstantPassword.ql
1918
ql/swift/ql/src/queries/Security/CWE-311/CleartextStorageDatabase.ql
2019
ql/swift/ql/src/queries/Security/CWE-311/CleartextTransmission.ql
2120
ql/swift/ql/src/queries/Security/CWE-312/CleartextLogging.ql
2221
ql/swift/ql/src/queries/Security/CWE-312/CleartextStoragePreferences.ql
23-
ql/swift/ql/src/queries/Security/CWE-321/HardcodedEncryptionKey.ql
2422
ql/swift/ql/src/queries/Security/CWE-327/ECBEncryption.ql
2523
ql/swift/ql/src/queries/Security/CWE-328/WeakPasswordHashing.ql
2624
ql/swift/ql/src/queries/Security/CWE-328/WeakSensitiveDataHashing.ql

swift/ql/integration-tests/posix/query-suite/swift-security-extended.qls.expected

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -15,12 +15,10 @@ ql/swift/ql/src/queries/Security/CWE-1204/StaticInitializationVector.ql
1515
ql/swift/ql/src/queries/Security/CWE-1333/ReDoS.ql
1616
ql/swift/ql/src/queries/Security/CWE-134/UncontrolledFormatString.ql
1717
ql/swift/ql/src/queries/Security/CWE-135/StringLengthConflation.ql
18-
ql/swift/ql/src/queries/Security/CWE-259/ConstantPassword.ql
1918
ql/swift/ql/src/queries/Security/CWE-311/CleartextStorageDatabase.ql
2019
ql/swift/ql/src/queries/Security/CWE-311/CleartextTransmission.ql
2120
ql/swift/ql/src/queries/Security/CWE-312/CleartextLogging.ql
2221
ql/swift/ql/src/queries/Security/CWE-312/CleartextStoragePreferences.ql
23-
ql/swift/ql/src/queries/Security/CWE-321/HardcodedEncryptionKey.ql
2422
ql/swift/ql/src/queries/Security/CWE-327/ECBEncryption.ql
2523
ql/swift/ql/src/queries/Security/CWE-328/WeakPasswordHashing.ql
2624
ql/swift/ql/src/queries/Security/CWE-328/WeakSensitiveDataHashing.ql
Lines changed: 4 additions & 0 deletions

swift/ql/src/queries/Security/CWE-259/ConstantPassword.ql

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@
44
* @kind path-problem
55
* @problem.severity error
66
* @security-severity 6.8
7-
* @precision high
7+
* @precision low
88
* @id swift/constant-password
99
* @tags security
1010
* external/cwe/cwe-259

swift/ql/src/queries/Security/CWE-321/HardcodedEncryptionKey.ql

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@
44
* @kind path-problem
55
* @problem.severity error
66
* @security-severity 8.1
7-
* @precision high
7+
* @precision low
88
* @id swift/hardcoded-key
99
* @tags security
1010
* external/cwe/cwe-321

0 commit comments

Comments
 (0)