Asger F
|
6423033db6
|
JS: Resolve inserted TODOs
|
2025-01-23 13:02:52 +01:00 |
|
Asger F
|
102b187c35
|
JS: Ignore experimental queries for now
|
2025-01-23 12:53:18 +01:00 |
|
Asger F
|
dba76a0e4d
|
JS: Rerun patch query after bugfix
|
2025-01-23 10:31:32 +01:00 |
|
Erik Krogh Kristensen
|
4bd4937e65
|
Merge pull request #18547 from erik-krogh/suffixCheck
JS: Fix FPs with js/incorrect-suffix-check
|
2025-01-22 21:13:27 +01:00 |
|
Asger F
|
051fa66af1
|
JS: Add change note
|
2025-01-22 11:49:48 +01:00 |
|
Asger F
|
4161f455b8
|
Revert "Add view-component-input for testing"
This reverts commit 6954039a6d106e3611a0892972a979fd45310d1a.
|
2025-01-22 10:45:52 +01:00 |
|
Asger F
|
e5c0390972
|
Add view-component-input for testing
|
2025-01-22 10:45:50 +01:00 |
|
Asger F
|
d647c7b14d
|
JS: Replace 'instanceof ClientSideRemoteFlowSource'
|
2025-01-22 10:45:49 +01:00 |
|
Asger F
|
3061d51b20
|
JS: Add ThreatModelSource#isCilentSideSource()
|
2025-01-22 10:45:48 +01:00 |
|
Asger F
|
327bdc0b02
|
JS: Use TypeScript types to restrict ViewComponentInputs in general
|
2025-01-22 10:45:47 +01:00 |
|
Asger F
|
b015c88c79
|
JS: Add view-component-input threat model
|
2025-01-22 10:45:46 +01:00 |
|
erik-krogh
|
04bbd5919a
|
add change-note
|
2025-01-22 10:16:11 +01:00 |
|
Asger F
|
01f7d45e2d
|
JS: Add meta query for reporting threat model sources
|
2025-01-22 09:51:32 +01:00 |
|
Asger F
|
30d192a1db
|
JS: Move getName() to a shared location
|
2025-01-22 09:51:32 +01:00 |
|
Asger F
|
0b9187d76c
|
JS: Add change note
|
2025-01-21 14:17:35 +01:00 |
|
Asger F
|
a9d21e70c2
|
JS: Bump extractor version string
|
2025-01-21 14:04:12 +01:00 |
|
Asger F
|
dd55460d7f
|
JS: Update test output
|
2025-01-21 14:03:30 +01:00 |
|
Asger F
|
784d07c95b
|
JS: Ensure embedded TypeScript is extracted even when not associated with a tsconfig
|
2025-01-21 14:02:32 +01:00 |
|
Asger F
|
f3b52adde6
|
JS: Add test showing DB-CHECK failure
|
2025-01-21 14:02:17 +01:00 |
|
erik-krogh
|
2f1bd75ee9
|
remove redundant cast
|
2025-01-21 09:51:14 +01:00 |
|
erik-krogh
|
17afab7d0f
|
support that two indexOf() calls use the same string-concatenation in getAnEquivalentIndexOfCall()
|
2025-01-21 09:43:57 +01:00 |
|
erik-krogh
|
d5529e3a7e
|
ensure an indexOf call is equivalent with itself. (getAUse() is used later to find matching indexOf calls)
|
2025-01-21 09:42:30 +01:00 |
|
erik-krogh
|
905d904543
|
add a few failing tests
|
2025-01-21 09:40:24 +01:00 |
|
github-actions[bot]
|
fbb7f0a0c6
|
Post-release preparation for codeql-cli-2.20.2
|
2025-01-20 21:11:14 +00:00 |
|
github-actions[bot]
|
a0512a50f2
|
Release preparation for version 2.20.2
|
2025-01-20 21:11:12 +00:00 |
|
Asger F
|
683ebcaf16
|
Revert "JS: Add dummy extension with an empty diff"
This reverts commit 6e9b95d4e85f4829e788400575570bdb65eda6f6.
|
2025-01-20 11:20:35 +01:00 |
|
Asger F
|
a948915bb0
|
JS: Add dummy extension with an empty diff
|
2025-01-20 11:20:33 +01:00 |
|
Asger F
|
7c29ea9dda
|
JS: Update ExternalAPIUsedwithUntrustedData
|
2025-01-20 11:20:32 +01:00 |
|
Asger F
|
ecbd7983ba
|
JS: Update DifferentKindsComparisonBypassQuery.qll
|
2025-01-20 11:20:31 +01:00 |
|
Asger F
|
29da1fb6c8
|
JS: Update ConditionalBypassQuery.qll
|
2025-01-20 11:20:30 +01:00 |
|
Asger F
|
8fe622f572
|
JS: Update PrototypePollutingFunction.ql
|
2025-01-20 11:20:29 +01:00 |
|
Asger F
|
fd763a0883
|
JS: Auto-patch diff informed queries
|
2025-01-20 11:20:27 +01:00 |
|
Asger F
|
aa0b9559bf
|
Merge pull request #18472 from asgerf/js/test-suite
JS: Port three tests to use the new post processing-based inline test expectations
|
2025-01-17 12:06:32 +01:00 |
|
Asger F
|
2c65946684
|
JS: Add setOtherInput example
|
2025-01-17 10:29:03 +01:00 |
|
Asger F
|
e983e26f68
|
JS: Add example with safe field
|
2025-01-17 10:28:07 +01:00 |
|
Asger F
|
7b3727b874
|
JS: Add change note
|
2025-01-17 10:27:02 +01:00 |
|
Asger F
|
37062763ae
|
JS: Bump extractor version string
|
2025-01-17 10:27:01 +01:00 |
|
Asger F
|
859783c08b
|
JS: Support [(ngModel)]
|
2025-01-17 10:26:57 +01:00 |
|
Asger F
|
d55c68c1f1
|
JS: Add test case with [(ngModel)]
|
2025-01-17 10:24:16 +01:00 |
|
Asger F
|
97f5559e64
|
JS: Recognise form input from NgForm
|
2025-01-17 10:22:20 +01:00 |
|
Asger F
|
1ec3a62242
|
JS: Add test with NgForm.value
|
2025-01-17 10:20:59 +01:00 |
|
Asger F
|
d4daa21318
|
JS: Add DOM event sources in Angular2 model
|
2025-01-17 10:20:22 +01:00 |
|
Asger F
|
b8ba50a9ac
|
JS: Add Angular test case in XssThroughDom
|
2025-01-17 10:12:42 +01:00 |
|
Asger F
|
6f46a34873
|
JS: Refactor domEventSource() into a Range class
|
2025-01-17 10:12:40 +01:00 |
|
Asger F
|
26a11efc5b
|
Merge branch 'main' into js/test-suite
|
2025-01-17 10:09:06 +01:00 |
|
Asger F
|
bd2febcf00
|
JS: Implementing new signature members in StepInputSig
|
2025-01-16 13:38:08 +01:00 |
|
Asger F
|
1964b347c7
|
Merge branch 'main' into js/test-suite
|
2025-01-16 13:19:07 +01:00 |
|
Asger F
|
6cd9752289
|
Merge pull request #18467 from github/js/shared-dataflow-branch
JS: Migrate to shared data flow library (targeting main!) 🚀
|
2025-01-16 11:28:57 +01:00 |
|
Geoffrey White
|
90faab456d
|
Merge pull request #18473 from geoffw0/sensitive2
Improve shared sensitive data library handling of snake_case variable names
|
2025-01-15 18:02:33 +00:00 |
|
Asger F
|
bc34a045d3
|
JS: Triage discrepancies and update test
|
2025-01-10 14:18:31 +01:00 |
|