GitHub Security Lab
|
df10a7e7f0
|
Merge branch 'main' into amammad-js-bombs
|
2024-01-25 11:23:38 +01:00 |
|
Sid Shankar
|
2d71294f61
|
Merge pull request #15256 from sidshank/change/adjust-extracted-files-diagnostics
Js/Py/Rb: Report any extracted file as successfully extracted
|
2024-01-17 11:04:06 -05:00 |
|
erik-krogh
|
1a8a70dc1b
|
mark the range [0-?] as good in the overly-large-range query
|
2024-01-17 13:11:57 +01:00 |
|
Sid Shankar
|
59098be8c4
|
Merge branch 'main' into change/adjust-extracted-files-diagnostics
|
2024-01-16 21:51:41 -05:00 |
|
Erik Krogh Kristensen
|
d782bd9b1f
|
Merge pull request #13624 from jorgectf/seclab/dotjs
JS: Add `dot.js` support
|
2024-01-11 14:57:19 +01:00 |
|
Sid Shankar
|
e30a0d1e83
|
JS: Report any extracted file as successfully extracted
|
2024-01-08 22:19:33 +00:00 |
|
erik-krogh
|
58dc14d5bb
|
update expected output
|
2024-01-04 11:38:58 +01:00 |
|
erik-krogh
|
a9f2b3fad6
|
promote PropsTaintStep to a PreCallGraphStep
|
2024-01-04 10:45:22 +01:00 |
|
erik-krogh
|
fe3e768414
|
update expected output of tests
|
2023-12-20 14:10:36 +01:00 |
|
Jorge
|
f8cfd698fa
|
Merge branch 'main' into seclab/dotjs
|
2023-12-19 10:44:52 +01:00 |
|
amammad
|
102f09aa23
|
extend tests
|
2023-12-10 20:33:00 +01:00 |
|
amammad
|
18d0b28024
|
v1
|
2023-12-10 20:27:21 +01:00 |
|
Tom Hvitved
|
28373e0fdf
|
JS: Adapt to changes in shared code
|
2023-12-10 11:25:43 +01:00 |
|
erik-krogh
|
e8f9e366d5
|
remove redundant imports for JS
|
2023-12-08 16:56:54 +01:00 |
|
amammad
|
1547cd0546
|
added inline tests, move to experimental dir
|
2023-12-05 18:59:46 +01:00 |
|
amammad
|
2c4d2d3069
|
Merge branch 'main' into amammad-js-CodeInjection_execa
|
2023-12-05 18:38:09 +01:00 |
|
amammad
|
67fb802f29
|
fix conflict
|
2023-12-05 18:37:50 +01:00 |
|
Jorge
|
8abd1d9855
|
Merge branch 'main' into seclab/dotjs
|
2023-11-30 19:42:18 +01:00 |
|
Rafael
|
1a05c2e704
|
Added Django test
|
2023-11-29 08:26:49 +01:00 |
|
erik-krogh
|
abb8d65483
|
Merge branch 'main' into amammad-js-SQLI
|
2023-11-23 21:17:58 +01:00 |
|
amammad
|
60b422a35c
|
fix second round of code review. improve documents, fix better-sqlite3 method
|
2023-11-23 14:01:38 +01:00 |
|
Maiky
|
d661f7f482
|
Add Flow Labels
|
2023-11-22 19:50:16 +01:00 |
|
amammad
|
5cc4206e00
|
add a temporary Query file to demonstrate unsuccessful usage of two DataFlow configs
|
2023-11-22 08:30:59 +01:00 |
|
amammad
|
eb552b7c93
|
add failingPositiveTests to inlinetests
|
2023-11-22 08:00:38 +01:00 |
|
amammad
|
0328a2986d
|
move TypeORM library file and tests to experimental
add inline tests :)
Fix TypeORM fuzzy method according to Review
|
2023-11-21 19:59:06 +01:00 |
|
Max Schaefer
|
2c5ce3216e
|
Merge pull request #14846 from github/max-schaefer/js/path-injection
Update qhelp for js/path-injection.
|
2023-11-21 13:50:41 +00:00 |
|
Max Schaefer
|
dfffa1e237
|
Apply suggestions from code review
Co-authored-by: Sam Browning <106113886+sabrowning1@users.noreply.github.com>
|
2023-11-21 10:07:11 +00:00 |
|
erik-krogh
|
dde9a7cd7e
|
Merge branch 'main' into ts53-ts
|
2023-11-20 20:31:00 +01:00 |
|
Max Schaefer
|
d147faba4e
|
Update qhelp for js/path-injection.
|
2023-11-20 11:58:00 +00:00 |
|
Rasmus Wriedt Larsen
|
43d9d2ceb7
|
Merge pull request #14603 from github/max-schaefer/broken-crypto-algorithm-link
JavaScript/Python/Ruby: Improve alert message for `*/weak-cryptographic-algorithm`.
|
2023-11-08 14:29:24 +01:00 |
|
amammad
|
0652afced3
|
update tests, updated qldoc and examples, upgrade all libraries to path-problem, update jsonwebtoken source and sinks
|
2023-11-07 08:25:25 +01:00 |
|
amammad
|
36f0a78450
|
fix typeorm test.ts according to Review
|
2023-11-06 16:23:35 +01:00 |
|
amammad
|
d7f1e19d40
|
fix sqlite.js test according to Review
|
2023-11-06 15:22:36 +01:00 |
|
amammad
|
cc5dd3180a
|
fix better-sqlite3 tests according to Review
|
2023-11-06 15:18:55 +01:00 |
|
Arthur Baars
|
7f4bcdfa64
|
Rename test files
|
2023-11-06 13:38:33 +01:00 |
|
Arthur Baars
|
4192d09e5c
|
Add tests for deprecated 'assert' syntax
|
2023-11-06 13:38:33 +01:00 |
|
Arthur Baars
|
b4d89f7554
|
Replace 'assert' with 'with' in QL test files
|
2023-11-06 13:38:33 +01:00 |
|
amammad
|
a9c8bc082f
|
delete CWE-321
|
2023-11-02 16:27:31 +01:00 |
|
amammad
|
faa483a282
|
move to CWE-347, update comments of tests
|
2023-11-02 16:24:58 +01:00 |
|
amammad
|
9da815a5c0
|
move to new CWE-321 directory, make saparate query files for each JWT pkg, create a path query for jsonwebtoken package which is not work correctly
|
2023-11-02 14:13:52 +01:00 |
|
erik-krogh
|
688afddaf2
|
Re-order expected test output of all JS tests
|
2023-10-31 16:38:22 +01:00 |
|
Arthur Baars
|
5cc94e1105
|
Express.js: add req.path as remote input source
|
2023-10-31 12:44:26 +01:00 |
|
Arthur Baars
|
21b7a51d0a
|
Add test case for req.path
|
2023-10-31 12:44:25 +01:00 |
|
Arthur Baars
|
1479509d93
|
Re-order expected test ouput
|
2023-10-31 12:44:25 +01:00 |
|
Max Schaefer
|
104700f6d3
|
Address review comment.
|
2023-10-27 10:19:28 +01:00 |
|
erik-krogh
|
302199a74a
|
fix TypeExprKinds crashing on a ThisExpression
|
2023-10-26 16:33:54 +02:00 |
|
Max Schaefer
|
741735cc83
|
Port changes to JavaScript.
|
2023-10-26 14:47:24 +01:00 |
|
Max Schaefer
|
2c7291336d
|
Move test files into right directory.
|
2023-10-26 12:16:52 +01:00 |
|
Max Schaefer
|
bb146a1758
|
JavaScript: Add support for rateLimit export from express-rate-limit package.
|
2023-10-26 12:14:57 +01:00 |
|
amammad
|
e3dbdc3887
|
add custom query builder and active record querybuilder support
|
2023-10-22 21:39:59 +02:00 |
|