Erik Krogh Kristensen
|
7fa41c438f
|
Merge pull request #18794 from erik-krogh/v-flag
JS: Add support for the regex V flag
|
2025-02-17 13:56:48 +01:00 |
|
Asger F
|
0ca9b2285b
|
Merge pull request #18740 from asgerf/js/more-precise-diff-informed
JS: Provide more precise related locations
|
2025-02-17 10:27:15 +01:00 |
|
Napalys
|
3ec038e7b6
|
JS: Added predicate to check if v flag is used on regular expression
|
2025-02-16 18:31:08 +01:00 |
|
Asger F
|
7df3e647d1
|
JS: Use US spelling
|
2025-02-14 10:28:55 +01:00 |
|
Asger F
|
26dcbf7a2a
|
JS: Migrate URLSearchParams model to flow summaries
|
2025-02-13 11:51:33 +01:00 |
|
Asger F
|
7e3f89842d
|
JS: Provide more precise related locations
|
2025-02-11 14:12:03 +01:00 |
|
Asger F
|
45242977a4
|
JS: Model query-string parsers that strip off ? or #
|
2025-02-11 10:41:23 +01:00 |
|
Anders Schack-Mulligen
|
0b5270979d
|
SSA: Remove the need for ExitBasicBlock in SSA.
|
2025-02-10 14:36:18 +01:00 |
|
Asger F
|
16f7373712
|
JS: Model dependency injection in Nest
|
2025-01-29 13:49:46 +01:00 |
|
Asger F
|
89ad737b2a
|
JS: Add internal extension points sources of class objects/instances
|
2025-01-29 13:49:44 +01:00 |
|
Paul Hodgkinson
|
f033f179f7
|
Merge branch 'main' into angular-sources-sinks
|
2025-01-24 15:46:48 +00:00 |
|
Asger F
|
1b7977bf90
|
Merge pull request #18466 from asgerf/js/view-component-inputs
JS: Add view-component-input threat model
|
2025-01-24 10:59:25 +01:00 |
|
aegilops
|
522f3d1337
|
Merge
|
2025-01-23 17:00:56 +00:00 |
|
Asger F
|
6423033db6
|
JS: Resolve inserted TODOs
|
2025-01-23 13:02:52 +01:00 |
|
Asger F
|
dba76a0e4d
|
JS: Rerun patch query after bugfix
|
2025-01-23 10:31:32 +01:00 |
|
Asger F
|
d647c7b14d
|
JS: Replace 'instanceof ClientSideRemoteFlowSource'
|
2025-01-22 10:45:49 +01:00 |
|
Asger F
|
3061d51b20
|
JS: Add ThreatModelSource#isCilentSideSource()
|
2025-01-22 10:45:48 +01:00 |
|
Asger F
|
327bdc0b02
|
JS: Use TypeScript types to restrict ViewComponentInputs in general
|
2025-01-22 10:45:47 +01:00 |
|
Asger F
|
b015c88c79
|
JS: Add view-component-input threat model
|
2025-01-22 10:45:46 +01:00 |
|
Asger F
|
7c29ea9dda
|
JS: Update ExternalAPIUsedwithUntrustedData
|
2025-01-20 11:20:32 +01:00 |
|
Asger F
|
ecbd7983ba
|
JS: Update DifferentKindsComparisonBypassQuery.qll
|
2025-01-20 11:20:31 +01:00 |
|
Asger F
|
29da1fb6c8
|
JS: Update ConditionalBypassQuery.qll
|
2025-01-20 11:20:30 +01:00 |
|
Asger F
|
fd763a0883
|
JS: Auto-patch diff informed queries
|
2025-01-20 11:20:27 +01:00 |
|
Asger F
|
859783c08b
|
JS: Support [(ngModel)]
|
2025-01-17 10:26:57 +01:00 |
|
Asger F
|
97f5559e64
|
JS: Recognise form input from NgForm
|
2025-01-17 10:22:20 +01:00 |
|
Asger F
|
d4daa21318
|
JS: Add DOM event sources in Angular2 model
|
2025-01-17 10:20:22 +01:00 |
|
Asger F
|
6f46a34873
|
JS: Refactor domEventSource() into a Range class
|
2025-01-17 10:12:40 +01:00 |
|
Asger F
|
bd2febcf00
|
JS: Implementing new signature members in StepInputSig
|
2025-01-16 13:38:08 +01:00 |
|
Asger F
|
6cd9752289
|
Merge pull request #18467 from github/js/shared-dataflow-branch
JS: Migrate to shared data flow library (targeting main!) 🚀
|
2025-01-16 11:28:57 +01:00 |
|
Geoffrey White
|
f8659c0a4e
|
Sync identical files.
|
2025-01-10 10:26:13 +00:00 |
|
aegilops
|
e7881a8c7f
|
Fix typo
|
2025-01-09 17:11:06 +00:00 |
|
aegilops
|
62599b2a12
|
Formatted
|
2025-01-09 17:02:37 +00:00 |
|
aegilops
|
98b4c35844
|
Set doc string on getElementNode predicate
|
2025-01-09 17:00:01 +00:00 |
|
Asger F
|
9c4d378a1d
|
JS: Remove TODO comment
It is not subsumed by the other case, both cases are needed
|
2025-01-09 10:17:16 +01:00 |
|
Asger F
|
3f2882e1c6
|
JS: Remove an obsolete comment
The RHS of an assignment actually has a post-update node now
|
2025-01-09 09:59:23 +01:00 |
|
Asger F
|
b2d62a080b
|
JS: Move a test failure explanation into the test suite
We have an issue for fixing the underlying problem
|
2025-01-09 09:57:44 +01:00 |
|
Asger F
|
d9da9444fa
|
JS: Rephrase TODO
This is useful info, but not something that can be fixed locally in this query, so a TODO comment isn't helping
|
2025-01-09 09:45:39 +01:00 |
|
Asger F
|
3def8ecdee
|
JS: Remove unimportant TODO
|
2025-01-09 09:43:03 +01:00 |
|
Asger F
|
388dd871e1
|
JS: Remove TODO tracked by an issue.
This requires changes to the shared data flow library, not something we should track with a TODO in the JS codebase
|
2025-01-09 09:41:40 +01:00 |
|
Asger F
|
8b060c4294
|
JS: Remove TODO about evaluating legacy steps
There is an issue for tracking this. It's not a small fix.
|
2025-01-09 09:40:29 +01:00 |
|
Asger F
|
a8f93cac05
|
JS: Remove obsolete comment
The test case actually has the correct result now
|
2025-01-09 09:39:32 +01:00 |
|
Asger F
|
dd37c474d8
|
JS: Remove mention of results from comments
|
2025-01-09 09:39:30 +01:00 |
|
Asger F
|
fb54a3bde8
|
JS: Remove obsolete TODO comment
|
2025-01-09 09:39:29 +01:00 |
|
Asger F
|
b29ee2acde
|
JS: Remove references to localFieldStep
These are tracked in https://github.com/github/codeql-javascript-team/issues/456
|
2025-01-09 09:39:27 +01:00 |
|
Asger F
|
7766f97232
|
JS: Remove obsolete TODO
|
2025-01-09 09:39:26 +01:00 |
|
Asger F
|
8ac08db5c2
|
JS: Remove TODOs about WithArrayElement not being a taint step
This isn't going to become a taint step, the workaround is the permanent solution
|
2025-01-09 09:39:23 +01:00 |
|
Asger F
|
3cc1525985
|
JS: Remove obsolete TODOs
|
2025-01-09 09:19:30 +01:00 |
|
Asger F
|
1997e0a7b6
|
Merge pull request #18427 from asgerf/jss/change-note
JS: Add migration guide and change note
|
2025-01-09 09:13:16 +01:00 |
|
aegilops
|
4b57d5feb2
|
Added XSS sink for innerHTML/outerHTML using new Angular attribute def
|
2025-01-08 16:36:46 +00:00 |
|
aegilops
|
2dc9e7bab7
|
Moved def from AngularJSCore to Angular2
|
2025-01-08 16:36:10 +00:00 |
|