@@ -241,7 +241,30 @@ private predicate summaryModelCsv(string row) {
241241 "org.apache.commons.io;IOUtils;false;write;;;Argument[0];Argument[1];taint" ,
242242 "org.apache.commons.io;IOUtils;false;writeChunked;;;Argument[0];Argument[1];taint" ,
243243 "org.apache.commons.io;IOUtils;false;writeLines;;;Argument[0];Argument[2];taint" ,
244- "org.apache.commons.io;IOUtils;false;writeLines;;;Argument[1];Argument[2];taint"
244+ "org.apache.commons.io;IOUtils;false;writeLines;;;Argument[1];Argument[2];taint" ,
245+ // constructor flow
246+ "java.io;File;false;File;;;Argument[0];ReturnValue;taint" ,
247+ "java.io;File;false;File;;;Argument[1];ReturnValue;taint" ,
248+ "java.net;URI;false;URI;(String);;Argument[0];ReturnValue;taint" ,
249+ "javax.xml.transform.stream;StreamSource;false;StreamSource;;;Argument[0];ReturnValue;taint" ,
250+ "javax.xml.transform.sax;SAXSource;false;SAXSource;(InputSource);;Argument[0];ReturnValue;taint" ,
251+ "javax.xml.transform.sax;SAXSource;false;SAXSource;(XMLReader,InputSource);;Argument[1];ReturnValue;taint" ,
252+ "org.xml.sax;InputSource;false;InputSource;;;Argument[0];ReturnValue;taint" ,
253+ "javax.servlet.http;Cookie;false;Cookie;;;Argument[0];ReturnValue;taint" ,
254+ "javax.servlet.http;Cookie;false;Cookie;;;Argument[1];ReturnValue;taint" ,
255+ "java.util.zip;ZipInputStream;false;ZipInputStream;;;Argument[0];ReturnValue;taint" ,
256+ "java.util.zip;GZIPInputStream;false;GZIPInputStream;;;Argument[0];ReturnValue;taint" ,
257+ "java.util;StringTokenizer;false;StringTokenizer;;;Argument[0];ReturnValue;taint" ,
258+ "java.beans;XMLDecoder;false;XMLDecoder;;;Argument[0];ReturnValue;taint" ,
259+ "com.esotericsoftware.kryo.io;Input;false;Input;;;Argument[0];ReturnValue;taint" ,
260+ "java.io;BufferedInputStream;false;BufferedInputStream;;;Argument[0];ReturnValue;taint" ,
261+ "java.io;DataInputStream;false;DataInputStream;;;Argument[0];ReturnValue;taint" ,
262+ "java.io;ByteArrayInputStream;false;ByteArrayInputStream;;;Argument[0];ReturnValue;taint" ,
263+ "java.io;ObjectInputStream;false;ObjectInputStream;;;Argument[0];ReturnValue;taint" ,
264+ "java.io;StringReader;false;StringReader;;;Argument[0];ReturnValue;taint" ,
265+ "java.io;CharArrayReader;false;CharArrayReader;;;Argument[0];ReturnValue;taint" ,
266+ "java.io;BufferedReader;false;BufferedReader;;;Argument[0];ReturnValue;taint" ,
267+ "java.io;InputStreamReader;false;InputStreamReader;;;Argument[0];ReturnValue;taint"
245268 ]
246269}
247270
0 commit comments