Asger F
|
64d39da5f8
|
JS: Accept Sources/Sink tags
|
2025-02-28 13:29:30 +01:00 |
|
Asger F
|
51b45598c4
|
JS: Move an alert and add query ID
|
2025-02-28 13:28:13 +01:00 |
|
Asger F
|
e91a046a17
|
JS: Mark a spurious alert
|
2025-02-28 13:28:12 +01:00 |
|
Asger F
|
9be041e27d
|
JS: Update OK-style comments to $-style
|
2025-02-28 13:27:28 +01:00 |
|
erik-krogh
|
37a1727043
|
fix example in clear-text-logging qhelp to actually be bad
|
2025-01-27 11:31:28 +01:00 |
|
Asger F
|
3acd4814de
|
Merge branch 'main' into js/shared-dataflow-merge-main
|
2024-12-19 10:14:38 +01:00 |
|
Napalys Klicius
|
9ca0fe4cbf
|
Update RegExp handling and add test case
Co-authored-by: erik-krogh <erik-krogh@github.com>
|
2024-11-28 14:13:40 +01:00 |
|
Napalys
|
e673348ed3
|
JS: now RegExp with unknown flags is not flagged as an issue within password Clear text storage of sensitive information
|
2024-11-28 11:26:56 +01:00 |
|
Napalys
|
a2c46749c6
|
JS: fixed issue where MaskingReplacer would work only with regexp literals but not objects
|
2024-11-28 11:26:55 +01:00 |
|
Napalys
|
1ca57cfb9d
|
JS: add test cases with RegExp object for MaskingReplacer, currently gives wrong results
|
2024-11-28 11:26:54 +01:00 |
|
Asger F
|
1243188825
|
JS: Update CleartextLogging with fixed FP
|
2024-10-29 08:32:11 +01:00 |
|
Erik Krogh Kristensen
|
724a31b746
|
fix comment that wasn't updated in test
Co-authored-by: Rasmus Wriedt Larsen <rasmuswriedtlarsen@gmail.com>
|
2022-11-10 15:56:44 +01:00 |
|
erik-krogh
|
e0bcfe2afb
|
add failing test
|
2022-11-09 11:30:31 +01:00 |
|
Erik Krogh Kristensen
|
431c995131
|
add support for the debug library
|
2021-06-02 23:11:15 +02:00 |
|
Erik Krogh Kristensen
|
9bcbedde46
|
update consistency comment in passwords.js
|
2020-07-08 09:55:00 +02:00 |
|
Erik Krogh Kristensen
|
8ff515a58d
|
address review feedback on MaskingReplacer
|
2019-11-16 15:20:42 +01:00 |
|
Erik Krogh Kristensen
|
4ec2070e48
|
remove property reads on process.env as a taint step, and add a barrier for masking replace calls
|
2019-11-16 15:20:42 +01:00 |
|
Erik Krogh Kristensen
|
850278c62f
|
some changes based on review. And change to only flag unknown reads of process.env
|
2019-11-16 15:20:42 +01:00 |
|
Erik Krogh Kristensen
|
68c30aaef3
|
add flowlabels to js/clear-text-logging
|
2019-11-16 15:20:42 +01:00 |
|
Erik Krogh Kristensen
|
14e4decffa
|
changes based on review feedback. No flow-labels yet
|
2019-11-16 15:20:42 +01:00 |
|
Erik Krogh Kristensen
|
297c71a64b
|
add process.env as source for js/clear-text-logging
|
2019-11-16 15:20:41 +01:00 |
|
Esben Sparre Andreasen
|
b780f82869
|
JS: sharpen js/clear-text-logging (ODASA-7485)
|
2018-11-22 13:38:43 +01:00 |
|
Esben Sparre Andreasen
|
2b9f5c3fa2
|
JS: remove check for test-environment in js/clear-text-logging
|
2018-08-21 22:32:52 +02:00 |
|
Esben Sparre Andreasen
|
3636708d30
|
JS: extract and expose StringConcatenationTaintStep in TaintTracking
|
2018-08-21 22:32:52 +02:00 |
|
Esben Sparre Andreasen
|
0c4fb15651
|
JS: add query js/cleartext-logging
|
2018-08-20 08:34:16 +02:00 |
|