Asger F
|
3455463e71
|
JS: Add instantiation boilerplate
Note that this commit won't compile on its own, but putting the boilerplate in its own commit
|
2023-10-13 12:42:40 +02:00 |
|
Asger F
|
c839822eb9
|
JS: Add PostUpdateNode
|
2023-10-13 12:42:40 +02:00 |
|
Asger F
|
01952f17bf
|
JS: Add some missing getContainer() predicates
|
2023-10-13 12:42:40 +02:00 |
|
Asger F
|
21300eef4c
|
JS:Add ConstructorThisArgumentNode
|
2023-10-13 12:42:40 +02:00 |
|
Asger F
|
b499c6075a
|
JS: Add Contents.qll
|
2023-10-13 12:42:40 +02:00 |
|
Asger F
|
79e7aae9f6
|
JS: Add TEarlyStageNode
|
2023-10-13 12:42:39 +02:00 |
|
Asger F
|
51ef0e5836
|
JS: Move TNode into a cached module
|
2023-10-13 12:42:39 +02:00 |
|
Arthur Baars
|
a9a21aa313
|
Rename DynamicImportExpr::getImport{Attributes => Options}
|
2023-10-12 13:00:39 +02:00 |
|
Arthur Baars
|
c28004f2a6
|
Rename 'getImportAssertion()' to 'getImportAttributes()' in QL library
|
2023-10-12 13:00:39 +02:00 |
|
Erik Krogh Kristensen
|
85bb14f04f
|
Merge pull request #14405 from erik-krogh/tagCall
JS: recognize tagged template literals as `DataFlow::CallNode`
|
2023-10-11 11:25:34 +02:00 |
|
Erik Krogh Kristensen
|
6377e92067
|
Update javascript/ql/lib/semmle/javascript/dataflow/DataFlow.qll
Co-authored-by: Asger F <asgerf@github.com>
|
2023-10-11 09:52:48 +02:00 |
|
amammad
|
242f7e1c53
|
update pg :)
|
2023-10-10 11:42:32 +02:00 |
|
amammad
|
bbeb7b39d7
|
add better-sqlite3
|
2023-10-10 11:17:04 +02:00 |
|
erik-krogh
|
f48b47c656
|
JavaScript: add import that populate the shared abstract classes
|
2023-10-09 09:14:55 +02:00 |
|
erik-krogh
|
c2942b37a7
|
JS: delete various outdated deprecations
|
2023-10-09 09:14:55 +02:00 |
|
erik-krogh
|
0d992a3d1f
|
delete old deprecated aliases of various regex libraries
|
2023-10-09 09:14:54 +02:00 |
|
erik-krogh
|
56e9eda2b9
|
fix performance by caching getArgument
|
2023-10-07 13:06:45 +02:00 |
|
erik-krogh
|
18e6a5491c
|
recognize tagged templates as DataFlow::CallNode
|
2023-10-06 21:14:00 +02:00 |
|
Asger F
|
162c477236
|
JS: Add AmdModuleDefinition::Range
|
2023-10-04 20:38:37 +02:00 |
|
amammad
|
97c27ac11b
|
revert SqlInjection.ql changes
|
2023-09-29 01:36:00 +10:00 |
|
amammad
|
58f4cd77dc
|
add TypeORM to javascript.qll file
add tests
improvement on comments
|
2023-09-29 01:23:22 +10:00 |
|
Anders Schack-Mulligen
|
855c89667d
|
JavaScript: Use shared FileSystem library.
|
2023-09-28 08:58:55 +02:00 |
|
amammad
|
0eb0c238f3
|
stash
|
2023-09-23 20:28:34 +10:00 |
|
amammad
|
bafe357500
|
V3
|
2023-09-23 18:22:43 +10:00 |
|
amammad
|
0c40223192
|
v1
|
2023-09-23 18:17:49 +10:00 |
|
amammad
|
a8aeb1d03e
|
add active record and data mapper patterns support
|
2023-09-22 22:50:55 +10:00 |
|
amammad
|
f1a7f0a7e8
|
V1
|
2023-09-22 19:21:41 +10:00 |
|
amammad
|
522a2e2594
|
v2
|
2023-09-22 18:56:47 +10:00 |
|
amammad
|
54a44777b7
|
v1
|
2023-09-13 19:14:15 +10:00 |
|
erik-krogh
|
a7d92b3473
|
add JS support the using keyword
|
2023-08-24 20:30:26 +02:00 |
|
Asger F
|
dec6039469
|
JS: Follow immediate predecessors in path resolution
|
2023-08-23 09:53:51 +02:00 |
|
yoff
|
7f2f6f14e7
|
Merge pull request #13729 from yoff/python/model-aws-lambdas
Python/JavaScript: Shared module for serverless functions
|
2023-08-16 15:14:08 +02:00 |
|
Asger F
|
c38cbe859d
|
Merge pull request #13737 from asgerf/dynamic/fuzzy-models
Dynamic: add Fuzzy token
|
2023-08-03 09:58:24 +02:00 |
|
Jeongsoo Lee
|
4529d8b75a
|
Add support for log injection in MaD
|
2023-07-28 22:37:56 +00:00 |
|
Asger F
|
d57276ca35
|
Merge pull request #13719 from asgerf/js/barrier-inout
JS: Replace barrier edges with barrier nodes
|
2023-07-13 16:36:52 +02:00 |
|
Asger F
|
f3fab587a9
|
JS: Add Fuzzy token in identifying access path
|
2023-07-13 14:01:06 +02:00 |
|
Asger F
|
7c9e1ad6ec
|
JS: Fix accidental recursion in Vue model
The API graph entry point depended on API::Node.
This was due to depending on the the TComponent newtype which has a branch that depends on API::Node
|
2023-07-13 13:41:21 +02:00 |
|
Rasmus Lerchedahl Petersen
|
02c41f3dcf
|
JavaScript: Use shared library for serverless
|
2023-07-12 16:46:34 +02:00 |
|
Asger F
|
c7abd4c2af
|
JS: Remove the unused edge-sanitizer hook in UnvalidatedDynamicMethodCall
|
2023-07-12 09:26:37 +02:00 |
|
Asger F
|
1a395c5b34
|
JS: Use sanitizerOut in PrototypePollutingAssignment
|
2023-07-11 15:24:10 +02:00 |
|
Asger F
|
b09ed4b0e3
|
JS: Update UnsafeJQueryPlugin
|
2023-07-11 15:01:33 +02:00 |
|
Asger F
|
a1d8a05bcb
|
JS: Update ResourceExhaustion
|
2023-07-11 14:56:53 +02:00 |
|
Asger F
|
58a557b18e
|
JS: Update InsecureRandomness
|
2023-07-11 14:56:43 +02:00 |
|
Asger F
|
e863e2376d
|
JS: Use sanitizerIn in ExtenralAPIUsedWithUntrustedData
|
2023-07-11 14:50:29 +02:00 |
|
Asger F
|
094302a27b
|
JS: Replace sanitizing prefix edge with node
|
2023-07-11 14:48:13 +02:00 |
|
Asger F
|
944a2ca825
|
JS: Replace ClearTextLogging::isSanitizerEdge with a node
|
2023-07-11 14:20:17 +02:00 |
|
Asger F
|
68584e549e
|
JS: Replace isOptionallySanitizedEdge with a node
|
2023-07-11 12:57:33 +02:00 |
|
Asger F
|
0841677b14
|
JS: Add isSanitizerX variants in TaintTracking
|
2023-07-11 11:14:37 +02:00 |
|
Asger F
|
d53beb3784
|
JS: Embed check for in/out barriers in edge barrier check
|
2023-07-11 11:04:28 +02:00 |
|
Asger F
|
4964d811a5
|
JS: Add interface for isBarrier in/out
|
2023-07-11 11:04:28 +02:00 |
|