Asger F
|
c637b6f59a
|
JS: Update test for RegExpAlwaysMatches
|
2023-05-26 14:10:26 +02:00 |
|
Asger F
|
9df9ca2916
|
JS: Update test and expectations for MissingRegExpAnchor
|
2023-05-26 14:07:34 +02:00 |
|
Asger F
|
40daa9c906
|
JS: Update RegExpInjection test and expectations
|
2023-05-26 14:05:36 +02:00 |
|
Asger F
|
2629ec1b1d
|
JS: Be more conservative about flagging "search" call arguments as regex
|
2023-05-26 11:55:53 +02:00 |
|
erik-krogh
|
9f5bf8fb22
|
also fix the first code-block
|
2023-05-25 13:56:29 +02:00 |
|
erik-krogh
|
765076bcba
|
fix whitespace in the samples in ReDoS.qhelp
|
2023-05-25 13:28:39 +02:00 |
|
github-actions[bot]
|
d2e192020b
|
Post-release preparation for codeql-cli-2.13.3
|
2023-05-24 11:26:12 +00:00 |
|
Erik Krogh Kristensen
|
796e71f8be
|
Merge pull request #13176 from MaxSchlueter/fixquery12
Fix "Introducing the JavaScript libraries" query12.qll and add test case
|
2023-05-24 10:56:53 +02:00 |
|
Arthur Baars
|
e33f3a6668
|
Merge pull request #13154 from aibaars/sync-dbscheme-py
JS/Ruby/QL/Python: sync dbscheme fragments
|
2023-05-23 19:14:29 +02:00 |
|
Max Schlueter
|
40aa9417d0
|
Fix query12 and add test case
|
2023-05-23 11:52:51 +02:00 |
|
erik-krogh
|
f7419c9250
|
add expected output
|
2023-05-23 09:56:06 +02:00 |
|
erik-krogh
|
f85b3e13c2
|
update expected output
|
2023-05-23 09:56:06 +02:00 |
|
Erik Krogh Kristensen
|
50cb5ea184
|
Merge pull request #13164 from erik-krogh/polyQhelp
ReDoS: add another example to the qhelp in poly-redos, showing how to just limit the length of the input
|
2023-05-23 09:25:15 +02:00 |
|
Erik Krogh Kristensen
|
e658177c31
|
Merge pull request #12975 from tyage/support-sub-modules
JS: Support sub modules
|
2023-05-23 09:24:43 +02:00 |
|
github-actions[bot]
|
7aa23cf11d
|
Release preparation for version 2.13.3
|
2023-05-22 20:47:00 +00:00 |
|
Erik Krogh Kristensen
|
653cd86c13
|
update qldoc
|
2023-05-22 20:48:21 +02:00 |
|
Arthur Baars
|
7978c65467
|
JS: add upgrade/downgrade scripts
|
2023-05-22 19:28:59 +02:00 |
|
Erik Krogh Kristensen
|
3647b9cfeb
|
Merge pull request #13196 from erik-krogh/indirectCommand
JS: require arguments to be shell interpreted to be flagged by indirect-command-injection
|
2023-05-22 11:53:57 +02:00 |
|
erik-krogh
|
708a99528f
|
initial implementation of TS 5.1
|
2023-05-22 10:11:32 +02:00 |
|
erik-krogh
|
710b309142
|
apply suggestions from doc review
|
2023-05-21 22:18:48 +02:00 |
|
erik-krogh
|
10bf17c33e
|
Merge branch 'main' into polyQhelp
|
2023-05-21 22:17:06 +02:00 |
|
Erik Krogh Kristensen
|
239234c5d2
|
fix bad change-note
Co-authored-by: Asger F <asgerf@github.com>
|
2023-05-17 14:47:32 +02:00 |
|
erik-krogh
|
5a82454710
|
add change-note
|
2023-05-17 12:02:21 +02:00 |
|
erik-krogh
|
cbd7601a41
|
implement isShellInterpreted on ExecActionsCall
|
2023-05-17 11:07:48 +02:00 |
|
erik-krogh
|
3293a55e8f
|
require arguments to be shell interpreted to be flagged by indirect-command-injection
|
2023-05-17 11:07:45 +02:00 |
|
Asger F
|
f94fdc6348
|
JS: Remove mention of TrackedNode in docs
|
2023-05-17 10:37:12 +02:00 |
|
erik-krogh
|
480e71fd69
|
avoid contractions
|
2023-05-17 08:42:45 +02:00 |
|
Jami Cogswell
|
003bb2f6f5
|
JS: add change note
|
2023-05-16 15:45:55 -04:00 |
|
Jami Cogswell
|
359f6ffd1e
|
JS: update 'credentials[%]' sink kind to 'credentials-%'
|
2023-05-16 15:45:55 -04:00 |
|
Jami Cogswell
|
7880e9e92c
|
JS: update 'command-line-injection' sink kind to 'command-injection'
|
2023-05-16 15:45:55 -04:00 |
|
Arthur Baars
|
2911a6cc30
|
JS: remove unused tables
|
2023-05-16 17:03:41 +02:00 |
|
Arthur Baars
|
fef0e1f1c8
|
JS: sync shared dbscheme fragments
|
2023-05-16 17:03:41 +02:00 |
|
erik-krogh
|
2ebce99eae
|
add another example of how to fix the prototype pollution issue
|
2023-05-15 17:24:02 +02:00 |
|
erik-krogh
|
7a338c408e
|
fix typo, the variable in the example is called items
|
2023-05-15 17:23:40 +02:00 |
|
erik-krogh
|
83ca1495e0
|
trim the whitespace in the poly-redos examples
|
2023-05-15 16:47:24 +02:00 |
|
erik-krogh
|
d989359656
|
add another example to the qhelp in poly-redos, showing how to just limit the length of the input
|
2023-05-15 16:47:02 +02:00 |
|
Asger F
|
20e8ee8423
|
Merge pull request #12748 from JarLob/yi
JS: Add more sources, more unit tests, fixes to the GitHub Actions injection query
|
2023-05-15 11:03:00 +02:00 |
|
tyage
|
93af0d0c2f
|
formatting
|
2023-05-13 17:37:31 +00:00 |
|
tyage
|
6f66c047d0
|
JS: ignoresub pkgs in node_modules directory
|
2023-05-13 09:12:28 +00:00 |
|
Max Schaefer
|
5dfe52afd0
|
Merge pull request #13152 from github/max-schaefer/unsafe-shell-command-construction-examples-sync
JavaScript: Use synchronous APIs in examples for js/shell-command-constructed-from-input.
|
2023-05-12 16:50:25 +01:00 |
|
Max Schaefer
|
2e7eb50319
|
JavaScript: Use synchronous APIs in examples for js/shell-command-constructed-from-input.
|
2023-05-12 14:42:11 +01:00 |
|
Max Schaefer
|
a4f6ccf2fc
|
JavaScript: Use gender-neutral language in qhelp for js/user-controlled-bypass
|
2023-05-12 14:21:40 +01:00 |
|
Kasper Svendsen
|
fe2f36a1fe
|
JS: Make implicit this receivers explicit
|
2023-05-12 12:12:48 +02:00 |
|
Kasper Svendsen
|
7dd9906e95
|
JS: Enable implicit this receiver warnings
|
2023-05-12 09:49:14 +02:00 |
|
Kasper Svendsen
|
189f8515c0
|
JS: Make implicit this receivers explicit
|
2023-05-12 09:49:14 +02:00 |
|
Kasper Svendsen
|
2184fefe7f
|
Merge pull request #13121 from kaspersv/kaspersv/javascript-explicit-this-receivers4
JS: Make implicit this receivers explicit
|
2023-05-12 08:21:52 +02:00 |
|
Kasper Svendsen
|
489a73c2c3
|
JS: Make implicit this receivers explicit
|
2023-05-11 11:50:56 +02:00 |
|
Erik Krogh Kristensen
|
71be426284
|
Merge pull request #13015 from kaspersv/kaspersv/js-explicit-this-receivers2
JS: Make implicit this receivers explicit
|
2023-05-11 10:39:11 +02:00 |
|
tyage
|
f6a8cd27ca
|
Update javascript/ql/lib/semmle/javascript/NPM.qll
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2023-05-10 19:36:49 +09:00 |
|
Asger F
|
f4b5f39c57
|
Merge pull request #13044 from cklin/javascript-locatable-tostring-join-ordering
JS: Add pragma[only_bind_out] to Locatable::toString() calls
|
2023-05-10 10:08:48 +02:00 |
|