Asger F
|
2b151cd587
|
JS: Include anchor direction in message
|
2019-11-15 09:27:20 +00:00 |
|
Asger F
|
3e952cf564
|
JS: Restrict semi-anchored regex query more
|
2019-11-15 09:27:19 +00:00 |
|
Asger F
|
0726bd8cac
|
JS: Add double semi-anchored test case
|
2019-11-15 09:27:19 +00:00 |
|
Asger F
|
9fa9729470
|
JS: Shift line numbers in SemiAnchoredRegExp testcase
|
2019-11-15 09:27:19 +00:00 |
|
Asger F
|
8bc89ee254
|
JS: Update semi-anchored regex query
|
2019-11-15 09:27:19 +00:00 |
|
Asger F
|
c21d095d38
|
JS: Restrict RegExp queries to actual regular expressions
|
2019-11-15 09:27:19 +00:00 |
|
Asger F
|
b8711fc642
|
JS: Extend RegExpTerm in ReDoS
|
2019-11-15 09:27:19 +00:00 |
|
Asger F
|
b6c1c174a9
|
JS: Deabstractify RegExpTerm classes
|
2019-11-15 09:27:19 +00:00 |
|
Asger F
|
e0bdc777b9
|
JS: Make ReDoS check string-based regexes
|
2019-11-15 09:27:19 +00:00 |
|
Asger F
|
97e5da1046
|
JS: Update ReDoS query
|
2019-11-15 09:27:19 +00:00 |
|
Asger F
|
57de6382cd
|
JS: Update QL API
|
2019-11-15 09:27:19 +00:00 |
|
Asger F
|
d3302c39c0
|
JS: Fix offsets in regexes parsed from strings with escapes
|
2019-11-15 09:27:19 +00:00 |
|
Asger F
|
2901b5e8bd
|
JS: Add OffsetTranslation table (preserving behavior)
|
2019-11-15 09:27:19 +00:00 |
|
Asger F
|
c327ee5d4f
|
JS: Update TRAP
|
2019-11-15 09:27:19 +00:00 |
|
Asger F
|
591fffc5cc
|
JS: Add test case for wide constants in char class
|
2019-11-15 09:27:19 +00:00 |
|
Asger F
|
68d23bcf8c
|
JS: Extract surrogate pairs as one constant node
|
2019-11-15 09:27:19 +00:00 |
|
Asger F
|
6e1c995f2f
|
JS: Merge consecutive constants in RegExps
|
2019-11-15 09:27:19 +00:00 |
|
Asger F
|
0e1246c0e5
|
JS: Extract RegExp ASTs from string literals
|
2019-11-15 09:27:18 +00:00 |
|
Asger F
|
0cf191f70d
|
JS: Bump extractor version string
|
2019-11-15 09:27:18 +00:00 |
|
Esben Sparre Andreasen
|
8e6a19b3d3
|
JS: add DefaultParsedCommandLineArgumentsAsSource
|
2019-11-15 08:42:02 +01:00 |
|
Esben Sparre Andreasen
|
2ea7d141c8
|
Merge pull request #2310 from max-schaefer/js/insufficient-url-scheme-check
JavaScript: Add query `IncompleteUrlSchemeCheck`
|
2019-11-14 22:13:02 +01:00 |
|
semmle-qlci
|
0638907825
|
Merge pull request #2324 from esbena/js/torrent-as-remote-source
Approved by max-schaefer
|
2019-11-14 20:28:07 +00:00 |
|
Max Schaefer
|
3b1e6c362c
|
JavaScript: Address review comments.
|
2019-11-14 17:11:59 +00:00 |
|
Erik Krogh Kristensen
|
e49b5e4afc
|
up precision from low to medium, and fix tab/spaces
|
2019-11-14 17:42:16 +01:00 |
|
Erik Krogh Kristensen
|
7137a64b7d
|
Added query for detecting XSS that happens through an exception
|
2019-11-14 17:04:00 +01:00 |
|
Esben Sparre Andreasen
|
cc768345d0
|
JS: add security tests for malicious torrents
|
2019-11-14 13:54:19 +01:00 |
|
Esben Sparre Andreasen
|
bea59ec8ad
|
JS: add some parsed torrent properties as remote flow sources
|
2019-11-14 13:54:19 +01:00 |
|
semmle-qlci
|
67963a5b9d
|
Merge pull request #2258 from asger-semmle/js-ignore-codesql-databases
Approved by esbena
|
2019-11-14 08:34:23 +00:00 |
|
Dave Bartolomeo
|
e89ecc19e3
|
Merge pull request #2302 from max-schaefer/test-qlpacks
Add `qlpack.yml` files for test folders.
|
2019-11-13 12:21:19 -07:00 |
|
Erik Krogh Kristensen
|
538690eee6
|
remove duplicate reflectiveCallNode method, and removing redundant getExpr() method
|
2019-11-13 15:53:21 +01:00 |
|
semmle-qlci
|
b11a7427c2
|
Merge pull request #2270 from erik-krogh/reflectiveExpr
Approved by max-schaefer
|
2019-11-13 13:08:40 +00:00 |
|
Max Schaefer
|
f804d316d7
|
Update javascript/ql/src/Security/CWE-020/IncompleteUrlSchemeCheck.ql
Co-Authored-By: Esben Sparre Andreasen <esbena@github.com>
|
2019-11-13 12:24:19 +00:00 |
|
Max Schaefer
|
ab583b7994
|
JavaScript: Add query IncompleteUrlSchemeCheck.ql.
|
2019-11-13 10:27:18 +00:00 |
|
Max Schaefer
|
155cea7b5b
|
Revert "JavaScript: Improve double-escaping query"
|
2019-11-12 22:54:12 +00:00 |
|
semmle-qlci
|
6c9f92666e
|
Merge pull request #2285 from asger-semmle/dataflow-syntax-examples
Approved by max-schaefer
|
2019-11-12 16:50:29 +00:00 |
|
Max Schaefer
|
5b2e32b051
|
Add qlpack.yml files for test folders.
|
2019-11-12 15:03:02 +00:00 |
|
Erik Krogh Kristensen
|
6f6c4c4fcc
|
fix tests after change from tabs to spaces
|
2019-11-12 08:48:01 +01:00 |
|
Erik Krogh Kristensen
|
67b38ed301
|
correctly weed out benign calls inside attributes
|
2019-11-11 15:30:33 +01:00 |
|
Felicity Chapman
|
c4f958d396
|
Merge pull request #2263 from sauyon/master
Update links to OWASP cheat sheet
|
2019-11-11 08:51:52 +00:00 |
|
Asger F
|
a2ff4e9494
|
JS: member -> property
|
2019-11-08 16:23:59 +00:00 |
|
Asger F
|
2a473fb9e7
|
Update javascript/ql/src/semmle/javascript/dataflow/Nodes.qll
Co-Authored-By: Max Schaefer <54907921+max-schaefer@users.noreply.github.com>
|
2019-11-08 16:15:08 +00:00 |
|
Asger F
|
4ad03a9061
|
Update javascript/ql/src/semmle/javascript/dataflow/DataFlow.qll
Co-Authored-By: Max Schaefer <54907921+max-schaefer@users.noreply.github.com>
|
2019-11-08 16:14:53 +00:00 |
|
Asger F
|
53d470da2f
|
JS: Add syntax examples to DataFlow classes
|
2019-11-08 15:51:26 +00:00 |
|
semmle-qlci
|
d9c7549dbe
|
Merge pull request #2279 from max-schaefer/js/touchstone-files
Approved by asger-semmle
|
2019-11-08 14:33:23 +00:00 |
|
Esben Sparre Andreasen
|
9b346b1d52
|
Merge pull request #2260 from max-schaefer/js/_min
JavaScript: Classify files with names ending in `_min` as minified.
|
2019-11-08 13:52:33 +01:00 |
|
semmle-qlci
|
867ed16777
|
Merge pull request #2276 from asger-semmle/inclusion-test
Approved by max-schaefer
|
2019-11-08 10:57:11 +00:00 |
|
Max Schaefer
|
d7831d2680
|
JavaScript: Short-circuit bad-header check on empty files.
|
2019-11-08 10:30:53 +00:00 |
|
Max Schaefer
|
e8510fe71a
|
TypeScript: Skip Touchstone files.
|
2019-11-08 09:17:05 +00:00 |
|
Asger F
|
812ee34bbc
|
JS: Use Files.exists() instead
|
2019-11-07 15:53:29 +00:00 |
|
semmle-qlci
|
e65271dfad
|
Merge pull request #2251 from asger-semmle/barrier-guard-improvements
Approved by esbena
|
2019-11-07 15:50:23 +00:00 |
|