Asger Feldthaus
|
389a3c9073
|
JS: Port CSRF query
|
2021-12-07 10:43:06 +01:00 |
|
Rasmus Wriedt Larsen
|
7ae1047fda
|
JS: Tag queries with CWE-328
CWE-328: Use of Weak Hash, see https://cwe.mitre.org/data/definitions/328.html
|
2021-12-06 14:02:24 +01:00 |
|
Erik Krogh Kristensen
|
a077345227
|
Merge pull request #7180 from erik-krogh/apiLabel2
JS: Make the edges of API-graphs into IPA types
|
2021-12-01 15:33:04 +01:00 |
|
github-actions[bot]
|
337ce65fe5
|
Release preparation for version 2.7.3
|
2021-11-30 20:39:35 +00:00 |
|
Dave Bartolomeo
|
96deddf053
|
JavaScript change notes
|
2021-11-29 16:16:30 -05:00 |
|
Dave Bartolomeo
|
d0dac03bad
|
Manually bump versions
|
2021-11-29 14:21:08 -05:00 |
|
Dave Bartolomeo
|
2dfcd1dd9c
|
Add groups property
Also removed versions from test packs
|
2021-11-29 14:15:53 -05:00 |
|
yoff
|
e63f9141e5
|
Merge pull request #7233 from RasmusWL/fix-cleartext-logging-cwes
JS/Py: Fix cleartext logging CWEs
|
2021-11-29 15:58:10 +01:00 |
|
Erik Krogh Kristensen
|
c13cad7e87
|
Merge branch 'main' into apiLabel2
|
2021-11-29 13:43:11 +01:00 |
|
Erik Krogh Kristensen
|
08ce03cd93
|
Merge branch 'main' into explicit-this
|
2021-11-24 15:24:58 +01:00 |
|
Rasmus Wriedt Larsen
|
c05ffd4d00
|
JS/PY: Remove CWE-315 form CleartextLogging
Since it is not relevant for this query:
CWE-315: Cleartext Storage of Sensitive Information in a Cookie
See https://cwe.mitre.org/data/definitions/315.html
|
2021-11-24 14:59:18 +01:00 |
|
Erik Krogh Kristensen
|
e9df860431
|
refactor implementation to make Label implementations private
|
2021-11-22 12:17:19 +01:00 |
|
Erik Krogh Kristensen
|
089d030bc2
|
make ApiLabel into a IPA type, and cache the public API of ApiGraphs
|
2021-11-22 09:03:33 +01:00 |
|
Erik Krogh Kristensen
|
011fc20963
|
use matches instead of regexpMatch
|
2021-11-18 15:41:25 +01:00 |
|
Erik Krogh Kristensen
|
1cca377e7d
|
Merge pull request #6561 from erik-krogh/htmlReg
JS/Py/Ruby: add a bad-tag-filter query
|
2021-11-18 09:39:13 +01:00 |
|
Erik Krogh Kristensen
|
f0c5a80d1a
|
apply the explicit this patch to new code
|
2021-11-13 21:03:54 +01:00 |
|
Erik Krogh Kristensen
|
0ff36cd083
|
Merge branch 'main' into explicit-this
|
2021-11-13 21:01:25 +01:00 |
|
Erik Krogh Kristensen
|
eef7709982
|
Merge pull request #7057 from erik-krogh/cwe598
JS: add js/sensitive-get-query query
|
2021-11-12 16:03:21 +01:00 |
|
Erik Krogh Kristensen
|
b513033e0f
|
Merge pull request #7021 from erik-krogh/cwe326
JS: Add insufficient key size query
|
2021-11-11 12:17:04 +01:00 |
|
Erik Krogh Kristensen
|
891694b50a
|
Merge pull request #5908 from erik-krogh/protoLib
JS: Add library input as source to js/prototype-polluting-assignment
|
2021-11-11 12:04:05 +01:00 |
|
Erik Krogh Kristensen
|
140a70f9df
|
Merge pull request #7029 from erik-krogh/cwe384
JS: add js/session-fixation query
|
2021-11-11 11:59:52 +01:00 |
|
Erik Krogh Kristensen
|
55434653f5
|
add CWE-532 to the clear-text-logging query
|
2021-11-10 14:15:49 +01:00 |
|
Erik Krogh Kristensen
|
ab5d9459c7
|
Update javascript/ql/src/Security/CWE-384/SessionFixation.qhelp
Co-authored-by: Ethan Palm <56270045+ethanpalm@users.noreply.github.com>
|
2021-11-10 08:24:46 +01:00 |
|
Erik Krogh Kristensen
|
330c2c42b5
|
Merge pull request #7075 from erik-krogh/cwe297
JS: add cwe-297 to `js/disabling-certificate-validation`
|
2021-11-08 14:35:58 +01:00 |
|
Erik Krogh Kristensen
|
a2175a3207
|
add cwe-297 to js/disabling-certificate-validation
|
2021-11-08 13:26:53 +01:00 |
|
Erik Krogh Kristensen
|
507c8addb2
|
add cwe-942 to js/cors-misconfiguration-for-credentials
|
2021-11-08 13:12:19 +01:00 |
|
Erik Krogh Kristensen
|
3d6a5263e0
|
improve qhelp
Co-authored-by: Esben Sparre Andreasen <esbena@github.com>
|
2021-11-08 12:02:39 +01:00 |
|
Erik Krogh Kristensen
|
02f500b9c2
|
Merge branch 'main' into htmlReg
|
2021-11-04 12:58:42 +01:00 |
|
Erik Krogh Kristensen
|
99f5f70345
|
Merge branch 'main' into protoLib
|
2021-11-04 12:53:53 +01:00 |
|
Erik Krogh Kristensen
|
bf5e36e9d4
|
fix docstring
Co-authored-by: Asger F <asgerf@github.com>
|
2021-11-04 12:46:24 +01:00 |
|
Erik Krogh Kristensen
|
4ba5ae09b0
|
add js/sensitive-get-query query
|
2021-11-04 12:30:44 +01:00 |
|
CodeQL CI
|
2895428d5b
|
Merge pull request #6714 from valeria-meli/javascript/ssrf
Approved by asgerf
|
2021-11-04 03:10:27 -07:00 |
|
luciaromeroML
|
e50938588e
|
formatting qll file
|
2021-11-03 10:30:35 -03:00 |
|
Erik Krogh Kristensen
|
264f4ab5ab
|
add js/session-fixation query
|
2021-11-03 13:04:41 +01:00 |
|
Erik Krogh Kristensen
|
9d99ce12c4
|
add CWE-497 to js/stack-trace-exposure
|
2021-11-02 15:43:55 +01:00 |
|
Erik Krogh Kristensen
|
076a3dca1f
|
add qhelp
|
2021-11-02 14:45:33 +01:00 |
|
Erik Krogh Kristensen
|
028799deb6
|
implement a simple InsufficientKeySize query
|
2021-11-02 14:45:30 +01:00 |
|
Erik Krogh Kristensen
|
54fba2d6a1
|
Merge pull request #6781 from erik-krogh/ldap
JS: Move LDAP injection out of experimental
|
2021-11-02 13:35:32 +01:00 |
|
Erik Krogh Kristensen
|
f7f315adbb
|
Merge pull request #7022 from erik-krogh/cwe319
JS: add cwe-319 to js/clear-text-cookie
|
2021-11-02 12:47:53 +01:00 |
|
Erik Krogh Kristensen
|
7a96b8e9e1
|
Merge branch 'main' into ldap
|
2021-11-02 12:47:28 +01:00 |
|
CodeQL CI
|
d5e2026a26
|
Merge pull request #6934 from erik-krogh/more-instanceof
Approved by MathiasVP, esbena, yoff
|
2021-11-02 03:46:23 -07:00 |
|
Erik Krogh Kristensen
|
41e7dea943
|
add cwe-319 "Cleartext Transmission of Sensitive Information" to js/clear-text-cookie
|
2021-11-02 11:11:38 +01:00 |
|
CodeQL CI
|
dde493259a
|
Merge pull request #7003 from asgerf/js/mixed-this-fp
Approved by erik-krogh
|
2021-11-01 09:13:21 +00:00 |
|
Erik Krogh Kristensen
|
db40ccae81
|
add explicit this to all member calls
|
2021-11-01 09:51:15 +01:00 |
|
Asger Feldthaus
|
d52b2bd863
|
JS: Fix FP in ˚MixedStaticInstanceThisAccess
|
2021-10-29 14:16:54 +02:00 |
|
Erik Krogh Kristensen
|
6fffdf6101
|
Merge pull request #6855 from erik-krogh/secCookie
JS: Move cookie queries out of experimental.
|
2021-10-29 10:23:48 +02:00 |
|
Erik Krogh Kristensen
|
cfc5629435
|
apply all doc fixes
Co-authored-by: hubwriter <hubwriter@github.com>
|
2021-10-28 18:19:37 +02:00 |
|
Erik Krogh Kristensen
|
d1238dfd8b
|
update alert message to distinguish between library input and remote flow
|
2021-10-27 20:35:38 +02:00 |
|
Erik Krogh Kristensen
|
71cca6d644
|
Merge branch 'main' into ldap
|
2021-10-27 19:06:06 +02:00 |
|
Erik Krogh Kristensen
|
44afa34e37
|
Merge branch 'main' of github.com:github/codeql into htmlReg
|
2021-10-26 14:46:27 +02:00 |
|