Add sink model for mkdirp and update tests for path injection alerts.

This commit is contained in:
Napalys
2025-04-02 16:29:18 +02:00
parent 533f1a93e2
commit 3fa24d6026
3 changed files with 42 additions and 9 deletions

View File

@@ -0,0 +1,6 @@
extensions:
- addsTo:
pack: codeql/javascript-all
extensible: sinkModel
data:
- ["mkdirp", "Member[nativeSync,native,manual,manualSync,mkdirpNative,mkdirpManual,mkdirpManualSync,mkdirpNativeSync,mkdirpSync].Argument[0]", "path-injection"]