Asger F
|
20e8ee8423
|
Merge pull request #12748 from JarLob/yi
JS: Add more sources, more unit tests, fixes to the GitHub Actions injection query
|
2023-05-15 11:03:00 +02:00 |
|
Kasper Svendsen
|
fe2f36a1fe
|
JS: Make implicit this receivers explicit
|
2023-05-12 12:12:48 +02:00 |
|
Kasper Svendsen
|
7dd9906e95
|
JS: Enable implicit this receiver warnings
|
2023-05-12 09:49:14 +02:00 |
|
Kasper Svendsen
|
189f8515c0
|
JS: Make implicit this receivers explicit
|
2023-05-12 09:49:14 +02:00 |
|
Asger F
|
c376eeb133
|
Merge pull request #12978 from asgerf/js/github-actions-sources
JS: Add sources and sinks related to GitHub Actions
|
2023-05-10 09:55:24 +02:00 |
|
Asger F
|
1a9956354e
|
JS: Restrict getInput to indirect command injection query
|
2023-05-03 16:10:03 +02:00 |
|
Kasper Svendsen
|
67950c8e6b
|
JS: Make implicit this receivers explicit
|
2023-05-03 15:31:00 +02:00 |
|
Asger F
|
b9ad4177f9
|
JS: List safe environment variables in IndirectCommandInjection
|
2023-05-03 10:48:14 +02:00 |
|
tyage
|
0d991574ec
|
Fix typo in test
|
2023-05-02 12:00:42 +09:00 |
|
Asger F
|
08785a4063
|
JS: Add sources from actions/core
|
2023-05-01 11:42:17 +02:00 |
|
Asger F
|
cb95dbfa14
|
JS: Add tests
|
2023-05-01 11:42:17 +02:00 |
|
Asger F
|
2c89f9747b
|
Merge pull request #12949 from asgerf/js/angular-native
JS: Add a few more DOM element sources
|
2023-05-01 11:08:45 +02:00 |
|
Asger F
|
e9f1e99526
|
Merge pull request #12887 from asgerf/js/unsafe-yaml-deserialization
JS: Update model of js-yaml
|
2023-05-01 09:57:20 +02:00 |
|
tyage
|
71952fe551
|
JS: Add test for sub module
|
2023-04-30 18:18:35 +09:00 |
|
Erik Krogh Kristensen
|
3d41cd583f
|
Merge pull request #12963 from tyage/track-interfile-use-router
JS: Track interfile useRouter
|
2023-04-28 22:41:43 +02:00 |
|
Asger F
|
d1c8e0abd7
|
Merge pull request #12951 from asgerf/js/json-with-comments
JS: Stop complaining about comments in JSON files
|
2023-04-28 20:53:35 +02:00 |
|
tyage
|
933b55d37d
|
Track interfile useRouter
|
2023-04-28 15:49:26 +09:00 |
|
Asger F
|
8a9308c8b0
|
JS: Update test output
|
2023-04-28 07:55:20 +02:00 |
|
Asger F
|
0c8f895e0f
|
JS: Add one more test
|
2023-04-27 21:06:20 +02:00 |
|
Asger F
|
97a942de80
|
JS: Update test output
|
2023-04-27 21:04:35 +02:00 |
|
Asger F
|
682ff23e04
|
JS: Update Express test
|
2023-04-27 16:36:04 +02:00 |
|
Asger F
|
410719fd9e
|
Update JSONError.expected
|
2023-04-27 10:57:38 +02:00 |
|
Asger F
|
cf1e87de9e
|
JS: Track DOM elements out of collections
|
2023-04-26 14:55:34 +02:00 |
|
Asger F
|
1f228a049f
|
JS: Add test for iterating over DOM collections
|
2023-04-26 14:54:38 +02:00 |
|
Asger F
|
0d74d88b7b
|
JS: Add new sink to test
|
2023-04-26 14:33:04 +02:00 |
|
Asger F
|
4df05b4e74
|
JS: Shift line numbers in test
|
2023-04-26 14:33:04 +02:00 |
|
Asger F
|
611a7060b4
|
JS: Add tests
|
2023-04-26 12:46:20 +02:00 |
|
Asger F
|
a446c5452d
|
JS: Update test output
|
2023-04-26 11:44:56 +02:00 |
|
Asger F
|
ff67118097
|
JS: Add hanging test case
|
2023-04-25 11:27:40 +02:00 |
|
jarlob
|
6e9f54ef55
|
Use double curly braces
|
2023-04-21 19:03:38 +02:00 |
|
Tom Hvitved
|
f6d000eb20
|
Merge pull request #12805 from hvitved/remove-queries-xml
Remove all `queries.xml` files
|
2023-04-18 10:52:14 +02:00 |
|
Asger F
|
13b1e97caa
|
JS: Fix the ExtendCall restriction
|
2023-04-17 12:30:08 +02:00 |
|
Asger F
|
eafef91dbc
|
JS: Update test output after ExtendCall restriction
|
2023-04-17 12:28:23 +02:00 |
|
Asger F
|
024760610a
|
JS: Add prototype pollution test
|
2023-04-17 12:27:34 +02:00 |
|
Asger F
|
04079752f7
|
JS: update test output after adding 'this' sanitizer
|
2023-04-17 12:15:46 +02:00 |
|
Asger F
|
f87f6c8556
|
JS: Add test to unsafe jquery plugin
|
2023-04-17 12:15:05 +02:00 |
|
Asger F
|
62dca44ee5
|
Update UntrustedDataToExternalAPI.expected
|
2023-04-17 08:23:04 +02:00 |
|
Asger F
|
b0d4b31103
|
JS: Trim whitespace in test
|
2023-04-17 08:23:04 +02:00 |
|
Asger F
|
c7f16cd224
|
JS: Add test
|
2023-04-17 08:23:03 +02:00 |
|
Erik Krogh Kristensen
|
cece307c60
|
Merge pull request #12802 from erik-krogh/history-xss
JS: add browser history as XSS sink
|
2023-04-14 13:35:19 +02:00 |
|
jarlob
|
d80c541da6
|
Encapsulate composite actions
|
2023-04-14 10:06:35 +02:00 |
|
Tom Hvitved
|
3cc9dec9c8
|
Remove all queries.xml files
|
2023-04-13 11:18:58 +02:00 |
|
Asger F
|
b819f55203
|
Merge pull request #12792 from asgerf/js/redux-model-perf
JS: add getForwardingFunction and use to sharpen useSelector model
|
2023-04-12 14:09:59 +02:00 |
|
erik-krogh
|
b1957623c1
|
add browser history as XSS sink
|
2023-04-12 13:38:18 +02:00 |
|
Asger F
|
2c65a49d7c
|
JS: Add getForwardingFunction() to API graphs
|
2023-04-11 14:00:30 +02:00 |
|
Asger F
|
4ce03d4dc4
|
JS: Restrict useSelector steps to local callbacks
|
2023-04-11 13:33:46 +02:00 |
|
Asger F
|
3cc931306f
|
JS: Add test for selector nodes with multiple access paths
|
2023-04-11 13:33:27 +02:00 |
|
tyage
|
320cb99dbf
|
Add replace method test
|
2023-04-08 18:31:48 +09:00 |
|
tyage
|
668e1accaa
|
Remove unnecessary whiteline
|
2023-04-08 18:24:31 +09:00 |
|
tyage
|
7f9b8557ac
|
Add Next.js router push as XSS sink
|
2023-04-08 18:18:34 +09:00 |
|