Asger F
|
024760610a
|
JS: Add prototype pollution test
|
2023-04-17 12:27:34 +02:00 |
|
Asger F
|
2f4a181a7d
|
JS: revert path sanitizers in proto pollution query
|
2023-04-17 12:21:00 +02:00 |
|
Asger F
|
04079752f7
|
JS: update test output after adding 'this' sanitizer
|
2023-04-17 12:15:46 +02:00 |
|
Asger F
|
f87f6c8556
|
JS: Add test to unsafe jquery plugin
|
2023-04-17 12:15:05 +02:00 |
|
Asger F
|
b728f71b4b
|
JS: Move 'this' sanitizer to customizations
|
2023-04-17 12:11:18 +02:00 |
|
Asger F
|
62dca44ee5
|
Update UntrustedDataToExternalAPI.expected
|
2023-04-17 08:23:04 +02:00 |
|
Asger F
|
c250ba7f27
|
JS: Undo sanitization of path.normalize()
|
2023-04-17 08:23:04 +02:00 |
|
Asger F
|
9db63c3a6a
|
JS: Change note
|
2023-04-17 08:23:04 +02:00 |
|
Asger F
|
b0d4b31103
|
JS: Trim whitespace in test
|
2023-04-17 08:23:04 +02:00 |
|
Asger F
|
c7f16cd224
|
JS: Add test
|
2023-04-17 08:23:03 +02:00 |
|
Asger F
|
0d598c437d
|
JS: Fix observed FPs in UnsafeJQueryPlugin
|
2023-04-17 08:20:18 +02:00 |
|
Asger F
|
b321151a28
|
JS: Restrict ExtendCall flow in proto pollution query
|
2023-04-17 08:20:18 +02:00 |
|
Asger F
|
efb582b661
|
JS: Drive-by fix to newly gained FPs
|
2023-04-17 08:20:18 +02:00 |
|
Asger F
|
869c6d27fe
|
JS: Add implied receiver steps
|
2023-04-17 08:20:18 +02:00 |
|
Asger F
|
74dbc71535
|
JS: Change Extend steps to PreCallGraphStep
|
2023-04-17 08:20:18 +02:00 |
|
github-actions[bot]
|
075d063370
|
Release preparation for version 2.13.0
|
2023-04-14 13:31:30 +00:00 |
|
jarlob
|
e9dee3a185
|
Move actions/github-script out of Actions.qll
|
2023-04-14 14:26:23 +02:00 |
|
Erik Krogh Kristensen
|
cece307c60
|
Merge pull request #12802 from erik-krogh/history-xss
JS: add browser history as XSS sink
|
2023-04-14 13:35:19 +02:00 |
|
jarlob
|
599ec5a3b4
|
Add comment
|
2023-04-14 10:52:11 +02:00 |
|
jarlob
|
3724ea1a7b
|
Extract where parts into predicates
|
2023-04-14 10:49:56 +02:00 |
|
jarlob
|
ac1c20673d
|
Encapsulate github-script
|
2023-04-14 10:23:49 +02:00 |
|
jarlob
|
d80c541da6
|
Encapsulate composite actions
|
2023-04-14 10:06:35 +02:00 |
|
smiddy007
|
ec97cdc8a0
|
Allow NonKeyCiphers to include truncated SHA-512 MDs in Forge JS library.
|
2023-04-13 23:16:20 -04:00 |
|
jarlob
|
94065764d5
|
Make predicate name clearer
|
2023-04-14 01:05:21 +02:00 |
|
jarlob
|
79218a3946
|
Use YamlMapping for modeling Env
|
2023-04-14 00:56:51 +02:00 |
|
jarlob
|
dd52ef85cd
|
Rename Env
|
2023-04-13 23:41:31 +02:00 |
|
jarlob
|
76834cbe53
|
Rename GlobalEnv
|
2023-04-13 23:13:56 +02:00 |
|
jarlob
|
a8a6913512
|
Simplify exists according to the warning
|
2023-04-13 23:10:16 +02:00 |
|
jarlob
|
8234ea33f0
|
More details in the changes file.
|
2023-04-13 23:05:32 +02:00 |
|
jarlob
|
6790318769
|
Added the composite word
|
2023-04-13 22:58:32 +02:00 |
|
Jaroslav Lobačevski
|
8f1bccbb4d
|
Apply suggestions from code review (comments)
Co-authored-by: Aditya Sharad <6874315+adityasharad@users.noreply.github.com>
|
2023-04-13 22:55:53 +02:00 |
|
Alex Eyers-Taylor
|
c6a482819a
|
Bump all qlpacks major versions
|
2023-04-13 19:15:27 +01:00 |
|
Alex Ford
|
8c46bfd051
|
Merge pull request #12816 from github/rc/3.9
Merge `rc/3.9` into `main`
|
2023-04-13 12:35:41 +01:00 |
|
Tom Hvitved
|
3cc9dec9c8
|
Remove all queries.xml files
|
2023-04-13 11:18:58 +02:00 |
|
Arthur Baars
|
ead8108aed
|
Apply suggestions from code review
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2023-04-13 11:11:55 +02:00 |
|
Erik Krogh Kristensen
|
cfb273ae01
|
Merge pull request #12799 from erik-krogh/oneColumn
JS: use 1-based column locations for diagnostics
|
2023-04-12 14:48:20 +02:00 |
|
Asger F
|
b819f55203
|
Merge pull request #12792 from asgerf/js/redux-model-perf
JS: add getForwardingFunction and use to sharpen useSelector model
|
2023-04-12 14:09:59 +02:00 |
|
erik-krogh
|
d3cc1d6991
|
update expected output of diagnostics test
|
2023-04-12 13:42:05 +02:00 |
|
erik-krogh
|
b1957623c1
|
add browser history as XSS sink
|
2023-04-12 13:38:18 +02:00 |
|
Erik Krogh Kristensen
|
8cb54b748b
|
Merge pull request #12787 from tyage/add-router-sink
JS: Add New XSS sink - Next.js router.push/replace
|
2023-04-12 13:30:21 +02:00 |
|
erik-krogh
|
fe5e4845b1
|
use 1-based column locations for diagnostics
|
2023-04-12 08:14:15 +02:00 |
|
Arthur Baars
|
83cd55cb29
|
Js/Yaml: add getFile() predicate
|
2023-04-11 16:01:44 +01:00 |
|
erik-krogh
|
3c4bd5b6a7
|
forward toString() etc. predicates from YamlNode to Locatable
|
2023-04-11 15:37:01 +02:00 |
|
erik-krogh
|
b5e90483f5
|
improve the ESLint model to avoid overriding Yaml classes
|
2023-04-11 15:36:18 +02:00 |
|
Asger F
|
aef0fa3c8a
|
JS: Expand QLDoc
|
2023-04-11 14:16:36 +02:00 |
|
Asger F
|
d702c7b990
|
Merge pull request #12759 from asgerf/js/getset-in-pattern
JS: Fix parsing of 'get' or 'set' pattern with a default value
|
2023-04-11 14:03:00 +02:00 |
|
Asger F
|
2c65a49d7c
|
JS: Add getForwardingFunction() to API graphs
|
2023-04-11 14:00:30 +02:00 |
|
Asger F
|
4ce03d4dc4
|
JS: Restrict useSelector steps to local callbacks
|
2023-04-11 13:33:46 +02:00 |
|
Asger F
|
3cc931306f
|
JS: Add test for selector nodes with multiple access paths
|
2023-04-11 13:33:27 +02:00 |
|
Nate Johnson
|
a0f4a5100f
|
Insecure HTTP parser query for JavaScript
|
2023-04-09 20:38:55 -04:00 |
|