Asger F
|
22b98c8959
|
JS: Restrict length of state path in vuex model
|
2023-06-14 15:48:58 +02:00 |
|
Jami
|
35591113c2
|
Merge branch 'main' into jcogs33/shared-sink-kind-validation
|
2023-06-14 08:06:34 -04:00 |
|
Asger F
|
f737054216
|
Merge pull request #13380 from asgerf/js/fix-sink-kind
JS: Fix invalid source kind in test
|
2023-06-14 12:56:58 +02:00 |
|
Asger F
|
5aea6fc16c
|
JS: Remove dataExtensions clause from test qlpack
|
2023-06-14 10:42:31 +02:00 |
|
Asger F
|
21831516f4
|
JS: use test-local data extensions
|
2023-06-14 10:38:33 +02:00 |
|
erik-krogh
|
3fd9f26b52
|
use consistent indentation in mongoose.js
|
2023-06-12 16:40:42 +02:00 |
|
erik-krogh
|
cd6f738f72
|
add mongoose.Types.ObjectId.isValid as a sanitizer-guard for NoSQL injection
|
2023-06-12 16:38:11 +02:00 |
|
Jami Cogswell
|
9abe3e3da4
|
Shared: use a module as input to 'KindValidation'
|
2023-06-09 14:35:37 -04:00 |
|
Jami Cogswell
|
da58b2afc8
|
Shared: move shared file to 'shared' folder and add parameterized module for 'getInvalidModelKind'
|
2023-06-08 20:05:27 -04:00 |
|
Jeroen Ketema
|
bff11c3d23
|
Apply suggestions from code review
|
2023-06-08 22:33:50 +02:00 |
|
github-actions[bot]
|
e4be303a23
|
Release preparation for version 2.13.4
|
2023-06-08 19:57:37 +00:00 |
|
Asger F
|
76a8e9827e
|
Merge pull request #13283 from asgerf/js/restrict-regex-search-function
JS: Be more conservative about flagging "search" call arguments as regex
|
2023-06-08 10:50:51 +02:00 |
|
Erik Krogh Kristensen
|
6ba7f9a238
|
Merge pull request #13352 from erik-krogh/once-again-deps-not-py-cpp
delete old deprecations
|
2023-06-07 13:00:57 +02:00 |
|
Asger F
|
17f9239c33
|
JS: Fix invalid source kind in test
|
2023-06-06 13:40:06 +02:00 |
|
Erik Krogh Kristensen
|
0e6693bdea
|
Merge pull request #12874 from erik-krogh/ts51
JS: Add support for TS 5.1
|
2023-06-06 11:51:51 +02:00 |
|
Erik Krogh Kristensen
|
b78cd48954
|
Merge pull request #13329 from erik-krogh/sqlhelp
JS: improve the sql-injection help page
|
2023-06-06 08:44:44 +02:00 |
|
Jami Cogswell
|
5a23421d9a
|
Shared: minor updates to comments
|
2023-06-05 13:46:56 -04:00 |
|
erik-krogh
|
3cb2ec4e87
|
fix nits from doc review
|
2023-06-05 19:06:07 +02:00 |
|
Jami Cogswell
|
9d5972acc2
|
Shared: update qldocs
|
2023-06-05 12:18:34 -04:00 |
|
Jami Cogswell
|
3f1dc8e5c7
|
Shared: add outdated Swift sink kinds
|
2023-06-05 12:18:34 -04:00 |
|
Jami Cogswell
|
62ac0dc471
|
Shared: add outdated sink kind msg to 'getInvalidModelKind' for all languages
|
2023-06-05 12:18:33 -04:00 |
|
Jami Cogswell
|
76f5dca861
|
Shared: move 'OutdatedSinkKind' to shared file and add outdated JS and C# sink kinds
|
2023-06-05 12:18:33 -04:00 |
|
Jami Cogswell
|
7b629f5d63
|
Shared: include 'qltest%' and 'test-%'
|
2023-06-05 12:18:33 -04:00 |
|
Jami Cogswell
|
254e447923
|
JS/Python/Ruby: update getInvalidModelKind
|
2023-06-05 12:18:33 -04:00 |
|
Jami Cogswell
|
7317c29eea
|
Shared: update kind information
|
2023-06-05 12:18:33 -04:00 |
|
Jami Cogswell
|
0ab1848b70
|
JS/Python/Ruby: use 'SharedModelValidation' file
|
2023-06-05 12:18:33 -04:00 |
|
Jami Cogswell
|
ddb5d92ef8
|
Shared: add source, summary, and neutral shared valid kinds
|
2023-06-05 12:18:33 -04:00 |
|
Jami Cogswell
|
869f820fcf
|
Shared: add 'SharedModelValidation' file as experiment
|
2023-06-05 12:18:33 -04:00 |
|
Jami Cogswell
|
e24e3a6115
|
JS/Python/Ruby: add getInvalidModelKind as experiment
|
2023-06-05 12:18:33 -04:00 |
|
Erik Krogh Kristensen
|
219ec9d05d
|
Merge pull request #13127 from erik-krogh/polReDoS
ReDoS: revert new superlinear algorithm.
|
2023-06-02 16:10:24 +02:00 |
|
erik-krogh
|
ac9ede4ec0
|
add change-notes
|
2023-06-02 11:58:11 +02:00 |
|
erik-krogh
|
f61b781386
|
JS: delete effectively empty file
|
2023-06-02 11:58:09 +02:00 |
|
erik-krogh
|
3584e85fe8
|
JS: fix tutorial
|
2023-06-02 11:58:08 +02:00 |
|
erik-krogh
|
9000243828
|
JS: fix compilation
|
2023-06-02 11:58:08 +02:00 |
|
erik-krogh
|
44b6366586
|
delete old deprecations
|
2023-06-02 11:58:08 +02:00 |
|
Asger F
|
77d2799278
|
Update javascript/ql/lib/semmle/javascript/Regexp.qll
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2023-06-02 10:33:44 +02:00 |
|
erik-krogh
|
1b44b59842
|
add stress test
|
2023-06-01 23:20:23 +02:00 |
|
erik-krogh
|
8eed1a95f6
|
stop recursive fromRhs related to getLaterBaseAccess
|
2023-06-01 23:16:52 +02:00 |
|
erik-krogh
|
97afa5733b
|
add support for namespaced JSX attributes
|
2023-06-01 21:52:14 +02:00 |
|
erik-krogh
|
f4b68fb8c3
|
bump TypeScript to stable version
|
2023-06-01 21:51:43 +02:00 |
|
Jami
|
3886ebffa9
|
Merge branch 'main' into jcogs33/update-javascript-sink-kinds
|
2023-06-01 14:09:10 -04:00 |
|
erik-krogh
|
9aeba4f31e
|
changes based on review
|
2023-06-01 17:24:44 +02:00 |
|
Erik Krogh Kristensen
|
96a720cfa0
|
Merge pull request #13285 from erik-krogh/redoshelp
ReDoS: fix whitespace in the samples in ReDoS.qhelp
|
2023-06-01 15:53:58 +02:00 |
|
Asger F
|
baef99995d
|
JS: Change note
|
2023-06-01 14:10:11 +02:00 |
|
erik-krogh
|
1e08105863
|
less duplicated headers in the sql-injection samples
|
2023-05-31 18:04:34 +02:00 |
|
erik-krogh
|
98820780af
|
show how to use mysql.escape in the sql-injection qhelp
|
2023-05-31 18:04:34 +02:00 |
|
erik-krogh
|
7d801e05ee
|
add an example of using dollar eq
|
2023-05-31 18:04:23 +02:00 |
|
erik-krogh
|
e24b45b423
|
elaborate on both SQL and NoSQL injection in the js/sql-injection qhelp
|
2023-05-31 09:57:38 +02:00 |
|
erik-krogh
|
b343dcaadd
|
put string/object in the alert-message for sql-injection
|
2023-05-31 08:06:04 +02:00 |
|
Arthur Baars
|
490d22d123
|
Merge remote-tracking branch 'upstream/main' into post-release-prep/codeql-cli-2.13.3
|
2023-05-30 21:31:28 +02:00 |
|