Napalys
|
e2927b2fad
|
Updated tanstack to use API graph.
|
2025-02-25 11:48:44 +01:00 |
|
Anders Schack-Mulligen
|
57c4fd6f25
|
JS: Combine phi reads and ssa input nodes into SynthReadNode class.
|
2025-02-25 09:23:53 +01:00 |
|
Anders Schack-Mulligen
|
1af753cd0c
|
JS: Use shared barrier guard for falsy check.
|
2025-02-24 13:00:06 +01:00 |
|
Anders Schack-Mulligen
|
09b2aeb53a
|
SSA: Replace use-use step implementation in data-flow integration.
|
2025-02-24 10:58:14 +01:00 |
|
Anders Schack-Mulligen
|
4e515bc2f5
|
JS: Remove reference to isInputInto
|
2025-02-21 14:48:24 +01:00 |
|
Napalys
|
3587ba593a
|
Add change note and added tanstack to supported framework list
|
2025-02-21 13:47:48 +01:00 |
|
Napalys
|
ab0241c1de
|
Added missing doc strings for Tanstack queries
|
2025-02-21 13:32:49 +01:00 |
|
Napalys
|
1227a7eedc
|
Add Tanstack framework support and enhance data flow tracking for fetch responses
|
2025-02-21 13:24:00 +01:00 |
|
Asger F
|
a1b7096125
|
Merge pull request #18783 from asgerf/js/downward-calls
JS: Resolve calls downward in class hierarchy
|
2025-02-20 09:01:58 +01:00 |
|
Asger F
|
58c8b5fa2b
|
Merge pull request #18790 from asgerf/js/no-implicit-array-taint
JS: Do not taint whole array when storing into ArrayElement
|
2025-02-19 13:23:31 +01:00 |
|
Asger F
|
e1c280500e
|
Merge pull request #18749 from Kwstubbs/express
JS: Add result.download to Express as Path Traversal Sink
|
2025-02-19 09:08:36 +01:00 |
|
Asger F
|
804a1a6cb0
|
JS: Handle array of sorting criteria
|
2025-02-18 16:58:04 +01:00 |
|
Asger F
|
7486742c37
|
JS: Fix model of _.sortBy
|
2025-02-18 16:53:40 +01:00 |
|
Asger F
|
ad4522c781
|
JS: Make 'typeStrongerThan' transitive
|
2025-02-18 16:04:48 +01:00 |
|
Asger F
|
e40ee821c2
|
JS: Update a qldoc comment
|
2025-02-18 16:02:47 +01:00 |
|
Asger F
|
e610683377
|
JS: Linter fix
|
2025-02-18 09:25:23 +01:00 |
|
github-actions[bot]
|
ad24f94a77
|
Post-release preparation for codeql-cli-2.20.5
|
2025-02-17 17:58:24 +00:00 |
|
github-actions[bot]
|
6f4562f3bd
|
Release preparation for version 2.20.5
|
2025-02-17 16:55:54 +00:00 |
|
Asger F
|
a54f0a74f1
|
JS: Target post-update node instead of getALocalSource
getAPropertyWrite() contains getALocalSource() under the the hood. Don't rely on that to find the successor of a mutation.
|
2025-02-17 15:00:02 +01:00 |
|
Asger F
|
6e074c301f
|
JS: Port lodash callback steps to flow summaries
Not all of lodash, just the callbacks we already modeled plus a few easy ones
|
2025-02-17 14:54:45 +01:00 |
|
Erik Krogh Kristensen
|
7fa41c438f
|
Merge pull request #18794 from erik-krogh/v-flag
JS: Add support for the regex V flag
|
2025-02-17 13:56:48 +01:00 |
|
Asger F
|
4e325d9f1c
|
JS: Convert some exception steps to legacy
|
2025-02-17 11:53:50 +01:00 |
|
Asger F
|
352924fb8c
|
JS: Handle a few other stringification contexts
|
2025-02-17 11:36:28 +01:00 |
|
Asger F
|
33ab7db98a
|
JS: Handle Array.prototype.toString calls
|
2025-02-17 11:25:03 +01:00 |
|
Asger F
|
d87534c7d0
|
JS: Model Array#toString
|
2025-02-17 11:13:36 +01:00 |
|
Asger F
|
0ca9b2285b
|
Merge pull request #18740 from asgerf/js/more-precise-diff-informed
JS: Provide more precise related locations
|
2025-02-17 10:27:15 +01:00 |
|
erik-krogh
|
6ebffd59f6
|
add change-note
|
2025-02-16 19:23:44 +01:00 |
|
Napalys
|
3ec038e7b6
|
JS: Added predicate to check if v flag is used on regular expression
|
2025-02-16 18:31:08 +01:00 |
|
Asger F
|
283954d515
|
JS: Do not store into arrays implicitly
|
2025-02-14 16:06:43 +01:00 |
|
Asger F
|
ab5fc9f4d7
|
JS: Implement viableImplInCallContext
|
2025-02-14 13:25:19 +01:00 |
|
Asger F
|
ff7bc7c25e
|
JS: Track types of classes in data flow
|
2025-02-14 12:44:45 +01:00 |
|
Asger F
|
b8b2b9a470
|
JS: Resolve calls downward in the class hierarchy
|
2025-02-14 11:17:19 +01:00 |
|
Asger F
|
7df3e647d1
|
JS: Use US spelling
|
2025-02-14 10:28:55 +01:00 |
|
Asger F
|
26dcbf7a2a
|
JS: Migrate URLSearchParams model to flow summaries
|
2025-02-13 11:51:33 +01:00 |
|
Kevin Stubbings
|
253882c3d1
|
Update javascript/ql/lib/change-notes/2025-02-12-express-download.md
Co-authored-by: Asger F <asgerf@github.com>
|
2025-02-12 11:01:29 -08:00 |
|
Kevin Stubbings
|
f5521ca1b8
|
Formatting
|
2025-02-12 00:15:27 -08:00 |
|
Kevin Stubbings
|
d0ed0fdeb3
|
Add download to Express
|
2025-02-12 00:10:09 -08:00 |
|
Asger F
|
7e3f89842d
|
JS: Provide more precise related locations
|
2025-02-11 14:12:03 +01:00 |
|
Asger F
|
45242977a4
|
JS: Model query-string parsers that strip off ? or #
|
2025-02-11 10:41:23 +01:00 |
|
Anders Schack-Mulligen
|
0b5270979d
|
SSA: Remove the need for ExitBasicBlock in SSA.
|
2025-02-10 14:36:18 +01:00 |
|
github-actions[bot]
|
f1b05a79a4
|
Post-release preparation for codeql-cli-2.20.4
|
2025-02-04 09:25:09 +00:00 |
|
github-actions[bot]
|
573e53e454
|
Release preparation for version 2.20.4
|
2025-02-03 15:19:35 +00:00 |
|
Asger F
|
16f7373712
|
JS: Model dependency injection in Nest
|
2025-01-29 13:49:46 +01:00 |
|
Asger F
|
89ad737b2a
|
JS: Add internal extension points sources of class objects/instances
|
2025-01-29 13:49:44 +01:00 |
|
Paul Hodgkinson
|
f033f179f7
|
Merge branch 'main' into angular-sources-sinks
|
2025-01-24 15:46:48 +00:00 |
|
Asger F
|
1b7977bf90
|
Merge pull request #18466 from asgerf/js/view-component-inputs
JS: Add view-component-input threat model
|
2025-01-24 10:59:25 +01:00 |
|
aegilops
|
c9a775d737
|
Merge branch 'angular-sources-sinks' of https://github.com/aegilops/codeql into angular-sources-sinks
|
2025-01-23 17:07:02 +00:00 |
|
aegilops
|
522f3d1337
|
Merge
|
2025-01-23 17:00:56 +00:00 |
|
Paul Hodgkinson
|
eacc322d4f
|
Update Angular Renderer2 XSS sink details in change note
|
2025-01-23 16:39:18 +00:00 |
|
Asger F
|
6423033db6
|
JS: Resolve inserted TODOs
|
2025-01-23 13:02:52 +01:00 |
|