aegilops
|
b4d8c4889a
|
Fixed wrong name for example HTML
|
2024-07-01 16:58:03 +01:00 |
|
aegilops
|
c985c9adb3
|
Added change note for polyfill.io query
|
2024-07-01 16:56:07 +01:00 |
|
aegilops
|
1744a98017
|
Added full stop to end of message
|
2024-07-01 16:53:22 +01:00 |
|
aegilops
|
ceda46e317
|
Fixed ending <p> tags
|
2024-07-01 16:52:28 +01:00 |
|
aegilops
|
a1b0703690
|
Added detection for specific Polyfill.io CDN compromise - edited existing library and added new query and tests
|
2024-07-01 16:21:34 +01:00 |
|
aegilops
|
fc6fba8d06
|
Fixed CWE tags
|
2024-07-01 14:25:47 +01:00 |
|
aegilops
|
d1d082982a
|
More external references
|
2024-07-01 14:25:29 +01:00 |
|
Arthur Baars
|
b12b33c8f9
|
Merge remote-tracking branch 'upstream/main' into 'rc/3.14'
|
2024-06-28 19:50:35 +02:00 |
|
Maiky
|
d0cf2a978c
|
Merge branch 'main' into maikypedia/javascript-cors
|
2024-06-27 20:24:42 +02:00 |
|
Asger F
|
ecf418b8f6
|
Merge branch 'main' into js/shared-dataflow
|
2024-06-25 11:48:41 +02:00 |
|
github-actions[bot]
|
fd385736e6
|
Post-release preparation for codeql-cli-2.17.6
|
2024-06-25 06:39:45 +00:00 |
|
github-actions[bot]
|
e32a587078
|
Release preparation for version 2.17.6
|
2024-06-24 14:33:10 +00:00 |
|
Erik Krogh Kristensen
|
db768960f4
|
Merge pull request #15060 from am0o0/amammad-js-envinjection
JS: Env Injection query
|
2024-06-20 21:27:21 +02:00 |
|
Erik Krogh Kristensen
|
555d7e5958
|
Merge pull request #14293 from am0o0/amammad-js-CodeInjection_dynamic_import
JS: Dynamic import as code injection sink
|
2024-06-20 21:19:57 +02:00 |
|
Erik Krogh Kristensen
|
e84028d01e
|
Merge pull request #14088 from am0o0/amammad-js-JWT
JS: decoding JWT without signature verification
|
2024-06-20 20:13:40 +02:00 |
|
aegilops
|
1ecd72727d
|
Renamed README to CUSTOMIZING, removed details from qhelp and referenced md doc instead
|
2024-06-19 17:59:43 +01:00 |
|
aegilops
|
a07639f4f6
|
Set severity to 7.0, in line with other configuration queries
|
2024-06-19 17:43:41 +01:00 |
|
aegilops
|
26f1b36736
|
Fixed formatting
|
2024-06-19 17:41:58 +01:00 |
|
aegilops
|
252c9e9416
|
Added data extension to set defaults, updated help, added README to explain customization
|
2024-06-19 17:27:17 +01:00 |
|
Paul Hodgkinson
|
3a98edb60b
|
Merge branch 'main' into aegilops/js/insecure-helmet-middleware
|
2024-06-19 12:53:32 +01:00 |
|
aegilops
|
d142f830da
|
Change note and changed name of query in .ql file
|
2024-06-19 12:04:32 +01:00 |
|
aegilops
|
8a3cec4977
|
Fix formatting for check
|
2024-06-19 11:38:20 +01:00 |
|
aegilops
|
de96d3951d
|
Renamed to helmetProperty everywhere
|
2024-06-19 10:15:06 +01:00 |
|
aegilops
|
f4691b1919
|
Changed to more-modern Dataflow libraries
|
2024-06-19 10:11:06 +01:00 |
|
aegilops
|
81ef255a87
|
Change to helmetProperty from helmetSetting variable name
|
2024-06-19 10:09:50 +01:00 |
|
aegilops
|
da9e1e61a4
|
Moved examples into separate files
|
2024-06-18 19:50:06 +01:00 |
|
am0o0
|
4e1f7a930d
|
fix invalid js file sample in qlhelp
|
2024-06-14 13:47:01 +02:00 |
|
am0o0
|
bb03a9faba
|
format the query file
|
2024-06-13 14:54:29 +02:00 |
|
am0o0
|
84b9d4d1ac
|
fix qlhelp errors
|
2024-06-13 14:32:41 +02:00 |
|
Maiky
|
8ba7ac678d
|
Update javascript/ql/src/experimental/Security/CWE-942/CorsPermissiveConfigurationCustomizations.qll
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2024-06-12 19:38:13 +02:00 |
|
Maiky
|
4be5cf4e78
|
Update javascript/ql/src/experimental/Security/CWE-942/CorsPermissiveConfigurationCustomizations.qll
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2024-06-12 19:38:02 +02:00 |
|
github-actions[bot]
|
8a25081a0e
|
Post-release preparation for codeql-cli-2.17.5
|
2024-06-10 15:33:08 +00:00 |
|
github-actions[bot]
|
877bfa2468
|
Release preparation for version 2.17.5
|
2024-06-10 13:40:39 +00:00 |
|
am0o0
|
9db334d02f
|
update select statement, update test cases
|
2024-06-07 21:26:20 +02:00 |
|
am0o0
|
5e0a78c4c7
|
make predicate for env key and value nodes, use propertyRead/Write instead of API nodes to find env key and value assignments, fix a bug thanks to @erik-krogh
|
2024-06-07 21:15:30 +02:00 |
|
aegilops
|
7ee5655f31
|
Merge branch 'aegilops/js/insecure-helmet-middleware' of https://github.com/aegilops/codeql into aegilops/js/insecure-helmet-middleware
|
2024-06-07 15:50:15 +01:00 |
|
aegilops
|
975811ae59
|
Change layout of qhelp example code
|
2024-06-07 15:50:06 +01:00 |
|
Paul Hodgkinson
|
43a140e62c
|
Merge branch 'main' into aegilops/js/insecure-helmet-middleware
|
2024-06-07 15:46:18 +01:00 |
|
aegilops
|
7136763c37
|
Formatting
|
2024-06-07 15:36:39 +01:00 |
|
aegilops
|
465d64a810
|
Removed br tags
|
2024-06-07 15:34:45 +01:00 |
|
aegilops
|
29322f5ff0
|
Merge branch 'aegilops/js/insecure-helmet-middleware' of https://github.com/aegilops/codeql into aegilops/js/insecure-helmet-middleware
|
2024-06-07 15:32:23 +01:00 |
|
aegilops
|
f5d465f08a
|
Added data extension to allow setting extra required Helmet features
|
2024-06-07 15:32:11 +01:00 |
|
am0o0
|
b9e3b3310e
|
update the remote flow based query thanks to @erik-krogh, update tests and separate the local and remote query tests
|
2024-06-07 06:01:49 +02:00 |
|
Am
|
af016f9416
|
Merge branch 'github:main' into amammad-js-JWT
|
2024-06-06 15:33:26 +03:30 |
|
am0o0
|
8258e377dd
|
use PascalCase for URLConstructorLabel
|
2024-06-06 14:00:56 +02:00 |
|
am0o0
|
d27a378008
|
change query-id to avoid duplicate ids
|
2024-06-06 13:59:58 +02:00 |
|
Am
|
e3e59e02e5
|
Merge branch 'github:main' into amammad-js-CodeInjection_dynamic_import
|
2024-06-04 16:22:06 +04:00 |
|
github-actions[bot]
|
906b65d09c
|
Post-release preparation for codeql-cli-2.17.4
|
2024-05-28 18:02:25 +00:00 |
|
github-actions[bot]
|
33b4ae8bbb
|
Release preparation for version 2.17.4
|
2024-05-28 15:44:32 +00:00 |
|
maikypedia
|
e96c3a36ad
|
Move Apollo to experimental
|
2024-05-27 12:24:48 +02:00 |
|