erik-krogh
|
6a2fa2e37d
|
add -dev to the codeql/typos version
|
2022-09-09 12:33:43 +02:00 |
|
erik-krogh
|
26d8553f6e
|
ensure consistent casing of names
|
2022-09-09 10:34:14 +02:00 |
|
Erik Krogh Kristensen
|
9893650f7c
|
Merge pull request #8604 from erik-krogh/httpNode
JS: refactor most library models away from AST nodes
|
2022-09-09 10:04:17 +02:00 |
|
erik-krogh
|
1ec77136ec
|
depend on an explicit version of the typo database
|
2022-09-09 08:37:38 +02:00 |
|
erik-krogh
|
aee72357b8
|
find a main module in more cases
|
2022-09-08 20:21:31 +02:00 |
|
erik-krogh
|
88f295fbb1
|
make a shared library of the typo database
|
2022-09-08 15:49:43 +02:00 |
|
erik-krogh
|
a21a4275f3
|
add taint-step in js/insecure-randomness for selecting a random element
|
2022-09-08 15:00:00 +02:00 |
|
github-actions[bot]
|
a9d80a5a48
|
Release preparation for version 2.10.5
|
2022-09-08 11:35:54 +00:00 |
|
erik-krogh
|
a35fe1ffab
|
Merge branch 'main' into js-followMsg
|
2022-09-08 13:09:15 +02:00 |
|
Erik Krogh Kristensen
|
57bf92a70c
|
Merge pull request #10347 from erik-krogh/mermaid
JS: add a markdown step through the `mermaid` library
|
2022-09-08 12:41:58 +02:00 |
|
Rasmus Wriedt Larsen
|
1d834799a2
|
Merge pull request #10114 from RasmusWL/shared-http-client-request
Ruby/Python: Shared HTTP client request concept
|
2022-09-08 11:58:06 +02:00 |
|
Erik Krogh Kristensen
|
9534f31eac
|
Merge pull request #10343 from erik-krogh/spreadFunction
JS: recognize calls to `Function` when spread arguments are used
|
2022-09-08 09:25:10 +02:00 |
|
erik-krogh
|
0407198dd2
|
add a markdown step through the mermaid library
|
2022-09-08 09:23:45 +02:00 |
|
Asger F
|
ada72b865f
|
Merge pull request #10332 from asgerf/js/type-confusion-bugfix
JS: bugfixes in TypeThroughThroughParameterTampering
|
2022-09-08 09:02:16 +02:00 |
|
erik-krogh
|
6447234428
|
recognize calls to Function where spread arguments are used
|
2022-09-07 22:55:51 +02:00 |
|
erik-krogh
|
e829387cdb
|
add failing test for call the Function with a spread argument
|
2022-09-07 22:54:21 +02:00 |
|
Asger F
|
6806bc1da4
|
JS: Expand test case
|
2022-09-07 14:18:01 +02:00 |
|
Asger F
|
6b2ebcce3a
|
Merge pull request #10276 from asgerf/mad-typedef-entry-points
Add TypeModel hook for adding MaD type-defs from CodeQL
|
2022-09-07 14:14:48 +02:00 |
|
Asger F
|
5c12780b1c
|
JS: Change note
|
2022-09-07 13:45:38 +02:00 |
|
Asger F
|
d31b59e61d
|
JS: Call super in isBarrier() override
|
2022-09-07 13:40:30 +02:00 |
|
Asger F
|
e3c84eefc1
|
JS: Correctly recognize Array.isArray calls
|
2022-09-07 13:39:52 +02:00 |
|
Asger F
|
3184ddb38a
|
JS: Fix test case
|
2022-09-07 13:39:51 +02:00 |
|
Asger F
|
0cc3b8a9ec
|
JS: Update test output
|
2022-09-06 18:48:14 +02:00 |
|
Asger F
|
e8864d072d
|
JS: Remove stray module DF export
|
2022-09-06 15:06:33 +02:00 |
|
Asger F
|
95c60858d4
|
Export as DataFlow instead of DF
|
2022-09-06 15:02:48 +02:00 |
|
erik-krogh
|
24f2e3cc07
|
update alert-messages of the sensitive data queries to match #10314
|
2022-09-06 12:25:36 +02:00 |
|
Rasmus Wriedt Larsen
|
a9e1e72196
|
Merge branch 'main' into shared-http-client-request
|
2022-09-06 10:52:27 +02:00 |
|
erik-krogh
|
0776687991
|
fix leftover todo in js/insecure-temporary-file
|
2022-09-06 10:05:50 +02:00 |
|
Asger F
|
f07e0592d0
|
JS: Drive-by fix for accidental recursion
|
2022-09-06 09:30:02 +02:00 |
|
Asger F
|
2cbba65617
|
JS: Sync with JS
fixup JS
|
2022-09-06 09:30:02 +02:00 |
|
Erik Krogh Kristensen
|
4e14177614
|
fix typo in change-note
|
2022-09-05 16:11:55 +02:00 |
|
Erik Krogh Kristensen
|
54eb0414cb
|
rename an upper-cased acronym
|
2022-09-05 16:11:55 +02:00 |
|
Erik Krogh Kristensen
|
90bc8a5038
|
run the explicit-this patch on javascript/
|
2022-09-05 16:11:55 +02:00 |
|
Erik Krogh Kristensen
|
b398f968e2
|
expand change-note to mention classes that have a changed basetype
|
2022-09-05 16:11:55 +02:00 |
|
Erik Krogh Kristensen
|
e64f96c1ce
|
rewrite the change-note to emphasise that the change is potentially breaking
|
2022-09-05 16:11:55 +02:00 |
|
Erik Krogh Kristensen
|
26f5643f3e
|
update the deprecation notice of RouteExpr such that it points to public APIs
|
2022-09-05 16:11:55 +02:00 |
|
Erik Krogh Kristensen
|
e387ebaedd
|
add domNode.innerHTML += sink as a DOM sink
|
2022-09-05 16:11:55 +02:00 |
|
Erik Krogh Kristensen
|
74a79f8622
|
simplify int check
Co-authored-by: Asger F <asgerf@github.com>
|
2022-09-05 16:11:55 +02:00 |
|
Erik Krogh Kristensen
|
73a936104a
|
fix typo in qldoc
Co-authored-by: Asger F <asgerf@github.com>
|
2022-09-05 16:11:55 +02:00 |
|
Erik Krogh Kristensen
|
833480d5c5
|
add change note
|
2022-09-05 16:11:55 +02:00 |
|
Erik Krogh Kristensen
|
5b61db9fd3
|
refactor miscellaneous expression uses to dataflow nodes
|
2022-09-05 16:11:55 +02:00 |
|
Erik Krogh Kristensen
|
6697dd1396
|
rewrite some expression based predicates in TaintTracking.qll
|
2022-09-05 16:11:55 +02:00 |
|
Erik Krogh Kristensen
|
b4968eb645
|
refactor the SensitiveExpr to be a dataflow node
|
2022-09-05 16:11:54 +02:00 |
|
Erik Krogh Kristensen
|
0c4f08c841
|
refactor the CredentialsExpr to be a dataflow node
|
2022-09-05 16:11:54 +02:00 |
|
Erik Krogh Kristensen
|
c5b1588096
|
update the SQL/NoSQL models to use dataflow nodes
|
2022-09-05 16:11:54 +02:00 |
|
Erik Krogh Kristensen
|
4d0534352e
|
refactor a use of MethodCallExpr in ClientSideUrlRedirectCustomizations.qll
|
2022-09-05 16:11:54 +02:00 |
|
Erik Krogh Kristensen
|
e0e8085b95
|
update the cryptoLibraries to use dataflow nodes
|
2022-09-05 16:11:54 +02:00 |
|
Erik Krogh Kristensen
|
5ebea8c75a
|
fix express in the POI test
|
2022-09-05 16:11:54 +02:00 |
|
Erik Krogh Kristensen
|
aa9261f1b1
|
convert the AngularJS model to use DataFlow nodes
|
2022-09-05 16:11:54 +02:00 |
|
Erik Krogh Kristensen
|
9bea110d24
|
convert the DOM model to use DataFlow nodes
|
2022-09-05 16:11:54 +02:00 |
|