Anders Schack-Mulligen
|
e36c59b285
|
ReDoS: Sync.
|
2022-05-31 11:04:42 +02:00 |
|
Erik Krogh Kristensen
|
6a6a63e1aa
|
Merge pull request #9354 from erik-krogh/jsStages
JS: collapse a few small stages
|
2022-05-30 20:31:54 +02:00 |
|
Asger F
|
c188aa87c7
|
Merge branch 'main' into js/madman-prep
|
2022-05-30 15:03:14 +02:00 |
|
Rasmus Wriedt Larsen
|
7a6646dcaf
|
Merge pull request #8883 from erik-krogh/pyMaD
Python: add MaD implementation
|
2022-05-30 13:31:07 +02:00 |
|
Asger F
|
5f42866de3
|
Merge pull request #9318 from asgerf/js/type-confusion-parmaeter-tampering-barrier
JS: Fix FP in js/type-confusion-through-parameter-tampering
|
2022-05-30 12:52:37 +02:00 |
|
Erik Krogh Kristensen
|
b700972e6f
|
fix bad join in XmlParers::getAResult
|
2022-05-30 12:37:51 +02:00 |
|
Max Schaefer
|
820dfac48c
|
Manually write out a transitive closure.
|
2022-05-30 12:37:50 +02:00 |
|
Max Schaefer
|
ea70aaff57
|
Improve detection of UMD modules.
We previously required the `define` to appear directly as an expression statement, but there are common patterns where this is not the case.
|
2022-05-30 12:37:50 +02:00 |
|
Max Schaefer
|
47e425a184
|
Improve inVoidContext to take conditional expressions into account.
|
2022-05-30 12:37:50 +02:00 |
|
Erik Krogh Kristensen
|
adb40f9360
|
Merge pull request #9289 from erik-krogh/es2022
JS: Support the remaining of the finished ES2022 proposals
|
2022-05-30 12:27:19 +02:00 |
|
Erik Krogh Kristensen
|
c7a8008897
|
Merge pull request #9235 from kaeluka/extractor-update-typescript-4_7
JS: Update the extractor to use TypeScript 4.7
|
2022-05-30 12:02:06 +02:00 |
|
Asger F
|
cc42f2f824
|
Merge pull request #8606 from asgerf/js/api-graph-api
JS/Python/Ruby: Document how API graphs should be interpreted
|
2022-05-30 10:49:14 +02:00 |
|
Asger F
|
468a4df215
|
Update javascript/ql/lib/semmle/javascript/security/dataflow/TypeConfusionThroughParameterTamperingQuery.qll
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2022-05-27 15:55:25 +02:00 |
|
Erik Krogh Kristensen
|
8c12a7289f
|
collapse a few small stages
|
2022-05-27 13:19:06 +02:00 |
|
Erik Krogh Kristensen
|
d199173923
|
add a getAPrimaryQlClass predicate to ExpressionWithTypeArguments
|
2022-05-25 16:10:13 +00:00 |
|
Asger F
|
5964be4463
|
Merge branch 'main' into js/type-confusion-parmaeter-tampering-barrier
|
2022-05-25 15:53:24 +02:00 |
|
Erik Krogh Kristensen
|
f38d1f9a4e
|
merge main into ts47
|
2022-05-25 10:13:25 +00:00 |
|
Asger F
|
877a9d8bcc
|
JS: Fix FP in js/type-confusion-through-parameter-tampering
|
2022-05-25 09:53:46 +02:00 |
|
github-actions[bot]
|
1f1b364feb
|
Release preparation for version 2.9.3
|
2022-05-25 07:46:48 +00:00 |
|
Asger F
|
ced1d21405
|
JS: Add getters for DeclarationSpace members
|
2022-05-24 14:30:36 +02:00 |
|
Asger Feldthaus
|
a5f2c949d3
|
JS: Add UnionOrIntersectionTypeExpr
|
2022-05-24 14:30:36 +02:00 |
|
Asger F
|
c8bb0e2117
|
JS: Treat d.ts as a single extension in Folder.getJavaScriptFile
|
2022-05-24 14:30:36 +02:00 |
|
Asger F
|
7d4a191a32
|
JS: Simplify
|
2022-05-24 14:18:06 +02:00 |
|
Asger F
|
db4b6d620a
|
JS: Remove Buffer.from as sink for js/resource-exhaustion
|
2022-05-24 14:18:05 +02:00 |
|
Erik Krogh Kristensen
|
82c6c22d50
|
make a model for hasOwnProperty calls and similar
|
2022-05-24 14:13:53 +02:00 |
|
Erik Krogh Kristensen
|
2a97dd9f6f
|
add support for Object.hasOwn(obj, key)
|
2022-05-24 13:59:25 +02:00 |
|
Erik Krogh Kristensen
|
1717d17fb3
|
add flow step for Array.prototype.at
|
2022-05-24 12:41:27 +02:00 |
|
Erik Krogh Kristensen
|
fc25d14af7
|
add change note
|
2022-05-24 12:37:28 +02:00 |
|
Asger F
|
631527fe49
|
JS: Rename Node.{getASource -> asSource, getASink -> asSink}
|
2022-05-24 11:57:30 +02:00 |
|
Asger F
|
bc601261ed
|
JS: Use 'ql' language for markdown snippets
|
2022-05-24 11:57:30 +02:00 |
|
Asger F
|
f80f8b6630
|
JS: Update a comment mentioning getARhs
|
2022-05-24 11:57:30 +02:00 |
|
Asger F
|
18dc39484d
|
Update javascript/ql/lib/semmle/javascript/ApiGraphs.qll
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2022-05-24 11:57:30 +02:00 |
|
Asger Feldthaus
|
1e96b1e559
|
JS: Fix typo
|
2022-05-24 11:57:30 +02:00 |
|
Asger Feldthaus
|
777d344dde
|
JS: Fix up qldoc for getAValueReachingSink
|
2022-05-24 11:57:30 +02:00 |
|
Asger Feldthaus
|
8da96ed403
|
JS: Update doc comment
|
2022-05-24 11:57:30 +02:00 |
|
Asger F
|
1ae97d9d54
|
Apply suggestions from code review
Co-authored-by: Nick Rolfe <nickrolfe@github.com>
|
2022-05-24 11:57:30 +02:00 |
|
Asger Feldthaus
|
9fad4b883b
|
JS: Autoformat
|
2022-05-24 11:57:30 +02:00 |
|
Asger Feldthaus
|
76ba78294f
|
JS: Make API::EntryPoint overrides optional
|
2022-05-24 11:57:30 +02:00 |
|
Asger Feldthaus
|
ce9c3b3eb5
|
JS: Also rename predicates on API::EntryPoint
|
2022-05-24 11:57:30 +02:00 |
|
Asger Feldthaus
|
19a5db9f89
|
JS: Rename getARhs -> getASink
|
2022-05-24 11:57:30 +02:00 |
|
Asger Feldthaus
|
4c6192670e
|
JS: Rename getAnImmediateUse -> getASource
|
2022-05-24 11:57:30 +02:00 |
|
Asger F
|
a7b73f44b2
|
Update javascript/ql/lib/semmle/javascript/ApiGraphs.qll
Co-authored-by: Calum Grant <42069085+calumgrant@users.noreply.github.com>
|
2022-05-24 11:57:30 +02:00 |
|
Asger F
|
73baa49c5d
|
Update javascript/ql/lib/semmle/javascript/ApiGraphs.qll
Co-authored-by: yoff <lerchedahl@gmail.com>
|
2022-05-24 11:57:30 +02:00 |
|
Asger Feldthaus
|
82c35e6f65
|
Mention that the interaction and be with any external codebase
|
2022-05-24 11:57:29 +02:00 |
|
Asger Feldthaus
|
6a12864dab
|
JS: Document how API graphs should be interpreted
|
2022-05-24 11:57:29 +02:00 |
|
Erik Krogh Kristensen
|
b2d3a7dca5
|
add change-note for the public renamed predicate
|
2022-05-24 11:20:08 +02:00 |
|
Erik Krogh Kristensen
|
a404a8c61a
|
use more set literals instead of big disjunctions
|
2022-05-24 11:09:10 +02:00 |
|
Erik Krogh Kristensen
|
b48806968c
|
delete redundant import
|
2022-05-24 11:02:41 +02:00 |
|
Erik Krogh Kristensen
|
395ec106b9
|
remove unused field
|
2022-05-24 11:02:18 +02:00 |
|
Erik Krogh Kristensen
|
d58fe8e193
|
add explicit this
|
2022-05-24 10:59:13 +02:00 |
|