Asger F
|
9c4d378a1d
|
JS: Remove TODO comment
It is not subsumed by the other case, both cases are needed
|
2025-01-09 10:17:16 +01:00 |
|
Asger F
|
3f2882e1c6
|
JS: Remove an obsolete comment
The RHS of an assignment actually has a post-update node now
|
2025-01-09 09:59:23 +01:00 |
|
Asger F
|
b2d62a080b
|
JS: Move a test failure explanation into the test suite
We have an issue for fixing the underlying problem
|
2025-01-09 09:57:44 +01:00 |
|
Asger F
|
d9da9444fa
|
JS: Rephrase TODO
This is useful info, but not something that can be fixed locally in this query, so a TODO comment isn't helping
|
2025-01-09 09:45:39 +01:00 |
|
Asger F
|
3def8ecdee
|
JS: Remove unimportant TODO
|
2025-01-09 09:43:03 +01:00 |
|
Asger F
|
388dd871e1
|
JS: Remove TODO tracked by an issue.
This requires changes to the shared data flow library, not something we should track with a TODO in the JS codebase
|
2025-01-09 09:41:40 +01:00 |
|
Asger F
|
8b060c4294
|
JS: Remove TODO about evaluating legacy steps
There is an issue for tracking this. It's not a small fix.
|
2025-01-09 09:40:29 +01:00 |
|
Asger F
|
a8f93cac05
|
JS: Remove obsolete comment
The test case actually has the correct result now
|
2025-01-09 09:39:32 +01:00 |
|
Asger F
|
dd37c474d8
|
JS: Remove mention of results from comments
|
2025-01-09 09:39:30 +01:00 |
|
Asger F
|
fb54a3bde8
|
JS: Remove obsolete TODO comment
|
2025-01-09 09:39:29 +01:00 |
|
Asger F
|
b29ee2acde
|
JS: Remove references to localFieldStep
These are tracked in https://github.com/github/codeql-javascript-team/issues/456
|
2025-01-09 09:39:27 +01:00 |
|
Asger F
|
7766f97232
|
JS: Remove obsolete TODO
|
2025-01-09 09:39:26 +01:00 |
|
Asger F
|
8ac08db5c2
|
JS: Remove TODOs about WithArrayElement not being a taint step
This isn't going to become a taint step, the workaround is the permanent solution
|
2025-01-09 09:39:23 +01:00 |
|
Asger F
|
3cc1525985
|
JS: Remove obsolete TODOs
|
2025-01-09 09:19:30 +01:00 |
|
Asger F
|
1997e0a7b6
|
Merge pull request #18427 from asgerf/jss/change-note
JS: Add migration guide and change note
|
2025-01-09 09:13:16 +01:00 |
|
aegilops
|
4b57d5feb2
|
Added XSS sink for innerHTML/outerHTML using new Angular attribute def
|
2025-01-08 16:36:46 +00:00 |
|
aegilops
|
2dc9e7bab7
|
Moved def from AngularJSCore to Angular2
|
2025-01-08 16:36:10 +00:00 |
|
Asger F
|
b6b93dcead
|
Merge pull request #18392 from asgerf/jss/deprecate-modules
JS: Deprecate some .qll files
|
2025-01-08 11:10:28 +01:00 |
|
Asger F
|
062391334e
|
JS: Remove notes about changing API in the future
|
2025-01-08 09:15:13 +01:00 |
|
Asger F
|
df9b95575e
|
JS: Add deprecation qldoc to Configuration classes
|
2025-01-08 09:15:12 +01:00 |
|
Asger F
|
e7d267e5d2
|
JS: Add migration guide and change note
|
2025-01-08 09:12:38 +01:00 |
|
Asger F
|
36f0d2f63e
|
JS: Move VarAccessBarrier outside the deprecated Configuration.qll file
|
2025-01-08 08:56:53 +01:00 |
|
Asger F
|
c47419e66d
|
JS: Remove an obsolete TODO comment (this has been fixed)
|
2025-01-08 08:54:41 +01:00 |
|
github-actions[bot]
|
fb20f6ca63
|
Post-release preparation for codeql-cli-2.20.1
|
2025-01-07 22:07:40 +00:00 |
|
github-actions[bot]
|
88b6f1e79a
|
Release preparation for version 2.20.1
|
2025-01-07 20:50:36 +00:00 |
|
Dave Bartolomeo
|
72a53c4b23
|
Revert "Release preparation for version 2.20.1"
|
2025-01-07 13:32:23 -05:00 |
|
github-actions[bot]
|
fbf9f2fff8
|
Release preparation for version 2.20.1
|
2025-01-07 17:20:13 +00:00 |
|
Dave Bartolomeo
|
22e030584c
|
Revert "Release preparation for version 2.20.1"
|
2025-01-07 12:14:27 -05:00 |
|
Asger F
|
f17cc5af15
|
JS: Move all hidden node definitions into DataFlowPrivate
|
2025-01-07 10:44:09 +01:00 |
|
Asger F
|
47cc3c09f5
|
JS: Deprecate an import
|
2025-01-07 10:43:40 +01:00 |
|
github-actions[bot]
|
a121c5a5d0
|
Release preparation for version 2.20.1
|
2025-01-06 18:20:22 +00:00 |
|
aegilops
|
4530118681
|
Comment out hardcoded definition of sink
|
2025-01-06 17:33:31 +00:00 |
|
aegilops
|
820fe6cd04
|
Formatting
|
2025-01-06 16:59:04 +00:00 |
|
aegilops
|
322c731ac3
|
Attempt at AttributeDefinition to generalise Angular Renderer2 support
|
2025-01-06 16:52:38 +00:00 |
|
aegilops
|
6fb201372b
|
Update changelog note to remove new source
|
2025-01-06 16:51:59 +00:00 |
|
aegilops
|
e414b8c5be
|
Remove @Input() decorated members as remote sources, in favour of a later Threat Model
|
2025-01-06 16:51:35 +00:00 |
|
aegilops
|
8dac00aa83
|
Change from getParameter() to getArgument()
|
2025-01-06 15:43:47 +00:00 |
|
Asger F
|
7ccb476b1b
|
JS: Restrict AP length in ExceptionXss
|
2025-01-06 14:28:58 +01:00 |
|
Asger F
|
23d7420cec
|
JS: Hide default exceptional return node
|
2025-01-06 14:27:20 +01:00 |
|
Asger F
|
e2af19b946
|
JS: Restrict "get" step to Map objects
|
2025-01-06 13:17:32 +01:00 |
|
Asger F
|
4c9f406e34
|
JS: Exclude some sinks in UnvalidatedDynamicMethodCall
|
2025-01-06 10:32:11 +01:00 |
|
aegilops
|
aba8be2902
|
Changelog for Angular source/sink update
|
2025-01-03 17:07:35 +00:00 |
|
aegilops
|
7128700003
|
Simplified AngularInputUse class
|
2025-01-03 17:02:55 +00:00 |
|
aegilops
|
4891c1e5fe
|
Added QLdoc and simplified QL in source class
|
2025-01-03 16:50:47 +00:00 |
|
aegilops
|
4773917876
|
Formatting
|
2025-01-03 16:43:00 +00:00 |
|
Paul Hodgkinson
|
a23f4ee007
|
Merge branch 'main' into angular-sources-sinks
|
2025-01-03 16:38:48 +00:00 |
|
aegilops
|
0f64822356
|
New remote source - reading from an @Input() decorated class member
|
2025-01-03 16:34:15 +00:00 |
|
aegilops
|
09e4c78b0f
|
New XSS sink - writing to innerHTML using the Angular Renderer2 API
|
2025-01-03 16:33:42 +00:00 |
|
Asger F
|
25f5ecba25
|
JS: Deprecate the Configuration.qll file
|
2025-01-03 11:41:41 +01:00 |
|
Asger F
|
0339bd0f3e
|
JS: Deprecate forward/backward exploration modules
|
2025-01-03 11:41:39 +01:00 |
|