github-actions[bot]
|
fa850cccb1
|
Release preparation for version 2.20.6
|
2025-03-03 17:13:19 +00:00 |
|
Asger F
|
a1b7096125
|
Merge pull request #18783 from asgerf/js/downward-calls
JS: Resolve calls downward in class hierarchy
|
2025-02-20 09:01:58 +01:00 |
|
Asger F
|
58c8b5fa2b
|
Merge pull request #18790 from asgerf/js/no-implicit-array-taint
JS: Do not taint whole array when storing into ArrayElement
|
2025-02-19 13:23:31 +01:00 |
|
Asger F
|
82a4b17218
|
JS: Change note
|
2025-02-18 09:43:08 +01:00 |
|
github-actions[bot]
|
ad24f94a77
|
Post-release preparation for codeql-cli-2.20.5
|
2025-02-17 17:58:24 +00:00 |
|
github-actions[bot]
|
6f4562f3bd
|
Release preparation for version 2.20.5
|
2025-02-17 16:55:54 +00:00 |
|
Asger F
|
0ca9b2285b
|
Merge pull request #18740 from asgerf/js/more-precise-diff-informed
JS: Provide more precise related locations
|
2025-02-17 10:27:15 +01:00 |
|
Asger F
|
b8f48aa711
|
JS: Change note
|
2025-02-17 10:24:57 +01:00 |
|
Asger F
|
c4724f42a3
|
JS: Change note
|
2025-02-13 11:51:35 +01:00 |
|
Asger F
|
7e3f89842d
|
JS: Provide more precise related locations
|
2025-02-11 14:12:03 +01:00 |
|
Asger F
|
7f4facc864
|
Merge pull request #18661 from asgerf/js/hoist-in-block
JS: Hoist function declarations to the top of a block statement
|
2025-02-06 12:38:51 +01:00 |
|
Asger F
|
6207e39b5f
|
JS: Change note
|
2025-02-06 09:58:24 +01:00 |
|
Remco Vermeulen
|
7619f1dac9
|
Merge pull request #18679 from rvermeulen/rvermeulen/ccr-suites
Add CCR suites
|
2025-02-05 09:35:48 -08:00 |
|
Anders Schack-Mulligen
|
bcec7ee234
|
Merge pull request #18633 from aschackmull/dataflow/refactor-flowstate
Dataflow: Refactor FlowState to be paired with Node
|
2025-02-05 09:43:25 +01:00 |
|
Remco Vermeulen
|
9894e9ef9f
|
Add CCR suites
|
2025-02-05 01:58:34 +00:00 |
|
Arthur Baars
|
2a32e8865d
|
Merge pull request #18668 from github/post-release-prep/codeql-cli-2.20.4
Post-release preparation for codeql-cli-2.20.4
|
2025-02-04 14:22:53 +01:00 |
|
Anders Schack-Mulligen
|
db1ed67e52
|
JS: Simplify config in PrototypePollutingFunction.ql.
|
2025-02-04 10:47:01 +01:00 |
|
github-actions[bot]
|
f1b05a79a4
|
Post-release preparation for codeql-cli-2.20.4
|
2025-02-04 09:25:09 +00:00 |
|
Asger F
|
09270f4e20
|
JS: Change note
|
2025-02-04 09:36:46 +01:00 |
|
github-actions[bot]
|
573e53e454
|
Release preparation for version 2.20.4
|
2025-02-03 15:19:35 +00:00 |
|
Asger F
|
a0af4c9a84
|
Merge pull request #18622 from asgerf/js/typescript-tsconfig-names
JS: Treat more file patterns as tsconfig-like files
|
2025-01-31 09:42:50 +01:00 |
|
Asger F
|
2e65fe9597
|
JS: Change note
|
2025-01-30 20:46:30 +01:00 |
|
Asger F
|
d23c198072
|
JS: Change note
|
2025-01-30 20:41:20 +01:00 |
|
Asger F
|
f8694a34e5
|
Merge pull request #18397 from aegilops/angular-sources-sinks
JavaScript CodeQL library updates: new Angular sink(s)
|
2025-01-29 09:09:23 +01:00 |
|
Erik Krogh Kristensen
|
87ad09bcdf
|
Merge pull request #18595 from erik-krogh/erik-krogh/clear-text-example
JS: fix example in clear-text-logging qhelp to actually be bad
|
2025-01-27 11:45:50 +01:00 |
|
erik-krogh
|
37a1727043
|
fix example in clear-text-logging qhelp to actually be bad
|
2025-01-27 11:31:28 +01:00 |
|
Paul Hodgkinson
|
f033f179f7
|
Merge branch 'main' into angular-sources-sinks
|
2025-01-24 15:46:48 +00:00 |
|
aegilops
|
d248551e88
|
Updated expected test result files using HEAD version of codeql
|
2025-01-24 15:46:09 +00:00 |
|
Asger F
|
1b7977bf90
|
Merge pull request #18466 from asgerf/js/view-component-inputs
JS: Add view-component-input threat model
|
2025-01-24 10:59:25 +01:00 |
|
Asger F
|
60f9160822
|
Merge pull request #18574 from asgerf/js/diff-informed2
JS: fix and improve diff-informed queries
|
2025-01-24 10:58:22 +01:00 |
|
aegilops
|
522f3d1337
|
Merge
|
2025-01-23 17:00:56 +00:00 |
|
Asger F
|
102b187c35
|
JS: Ignore experimental queries for now
|
2025-01-23 12:53:18 +01:00 |
|
Asger F
|
dba76a0e4d
|
JS: Rerun patch query after bugfix
|
2025-01-23 10:31:32 +01:00 |
|
Erik Krogh Kristensen
|
4bd4937e65
|
Merge pull request #18547 from erik-krogh/suffixCheck
JS: Fix FPs with js/incorrect-suffix-check
|
2025-01-22 21:13:27 +01:00 |
|
Asger F
|
051fa66af1
|
JS: Add change note
|
2025-01-22 11:49:48 +01:00 |
|
erik-krogh
|
04bbd5919a
|
add change-note
|
2025-01-22 10:16:11 +01:00 |
|
Asger F
|
01f7d45e2d
|
JS: Add meta query for reporting threat model sources
|
2025-01-22 09:51:32 +01:00 |
|
Asger F
|
30d192a1db
|
JS: Move getName() to a shared location
|
2025-01-22 09:51:32 +01:00 |
|
Asger F
|
0b9187d76c
|
JS: Add change note
|
2025-01-21 14:17:35 +01:00 |
|
erik-krogh
|
2f1bd75ee9
|
remove redundant cast
|
2025-01-21 09:51:14 +01:00 |
|
erik-krogh
|
17afab7d0f
|
support that two indexOf() calls use the same string-concatenation in getAnEquivalentIndexOfCall()
|
2025-01-21 09:43:57 +01:00 |
|
erik-krogh
|
d5529e3a7e
|
ensure an indexOf call is equivalent with itself. (getAUse() is used later to find matching indexOf calls)
|
2025-01-21 09:42:30 +01:00 |
|
github-actions[bot]
|
fbb7f0a0c6
|
Post-release preparation for codeql-cli-2.20.2
|
2025-01-20 21:11:14 +00:00 |
|
github-actions[bot]
|
a0512a50f2
|
Release preparation for version 2.20.2
|
2025-01-20 21:11:12 +00:00 |
|
Asger F
|
8fe622f572
|
JS: Update PrototypePollutingFunction.ql
|
2025-01-20 11:20:29 +01:00 |
|
Asger F
|
fd763a0883
|
JS: Auto-patch diff informed queries
|
2025-01-20 11:20:27 +01:00 |
|
Asger F
|
7b3727b874
|
JS: Add change note
|
2025-01-17 10:27:02 +01:00 |
|
Asger F
|
6cd9752289
|
Merge pull request #18467 from github/js/shared-dataflow-branch
JS: Migrate to shared data flow library (targeting main!) 🚀
|
2025-01-16 11:28:57 +01:00 |
|
Erik Krogh Kristensen
|
70a1a6454d
|
Merge pull request #18452 from asgerf/js/import-spec-strings
JS: Fix crash in case of string literal in export specifier
|
2025-01-09 15:50:40 +01:00 |
|
Asger F
|
a7fbfb2c2d
|
JS: Change note
|
2025-01-09 10:48:52 +01:00 |
|