- GitHub Staff
- Barcelona
- https://atorralba.github.io
- @_atorralba
Highlights
- 2 discussions answered
Block or Report
Block or report atorralba
Report abuse
Contact GitHub support about this user’s behavior. Learn more about reporting abuse.
Report abusePinned
-
GHSL_CTF_4 Public
My solution for GitHub Security Lab CTF 4: CodeQL and Chill - The Java Edition
1,396 contributions in the last year
Activity overview
Contribution activity
May 2022
Created 35 commits in 1 repository
Created a pull request in github/codeql that received 15 comments
Java: Add OkHttp and Retrofit models
Adds sinks of kind open-url and summaries for the libraries OkHttp and Retrofit.
Also simplifies the query java/non-https-urls to also consider sin…
+6,173
−11
•
15
comments
Opened 7 other pull requests in 1 repository
github/codeql
5
merged
1
closed
1
open
- Java: Remove org.dom4j.DocumentHelper:parseText as XXE sink
- Kotlin: Fix test to correctly highlight lack of flow from field init
- Kotlin: Add support for InlineExpectationsTest
- Kotlin: Add failing test for missing field flow
- Java: Add Expr::getUnderlyingExpr predicate
- Java: Sensitive Info Log query improvements
- Java: Make more ExternalFlow imports private
Reviewed 22 pull requests in 1 repository
github/codeql
22 pull requests
- Java: Add sources for Android external storage
- Java: Update commons-io SHA for model regeneration and update models.
- Kotlin: Adjust diagnostic message severity
- Java: Performance fixes for local flow relation
- Kotlin: exclude Kotlin source from 'inner class could be static' check
-
Kotlin: Exclude operands of
NotNullExprfrom NullMaybe query - Kotlin: Add more type check casts to MissingInstanceofInEquals query
-
Kotlin: Respect
overridemodifier in useless parameter query - Kotlin: Fix initializer field flow by extracting field finality
- Java: Sensitive Info Log query improvements
- Claim Go 1.18 support
- Kotlin: Apply changes since https://github.com/github/codeql/pull/9109 branched away from kotlin-main
- Update CSV framework coverage reports
- QL for QL: generalise non-US spelling query
- Kotlin: QLDoc tweaks from intrigus
- Fix non-US spellings and the corresponding query
- Initial Kotlin support
- Java: CWE-321 Query to detect hardcoded JWT secret keys
- Java: Add OkHttp and Retrofit models
- Java: Improvements to UnsafeAndroidAccess
- Java: Add CWE-377 tag to java/predictable-seed
- Update CSV framework coverage reports
Answered 2 discussions in 1 repository
27
contributions
in private repositories
May 4 – May 24

