Erik Krogh Kristensen
|
9178f4b1c5
|
add support for the anser library
|
2021-04-27 15:57:17 +02:00 |
|
edvraa
|
3aec9c1a41
|
Cookies without HttpOnly
|
2021-04-27 16:28:32 +03:00 |
|
CodeQL CI
|
635fb4c25a
|
Merge pull request #5685 from erik-krogh/markdownIt
Approved by asgerf
|
2021-04-22 14:55:31 -07:00 |
|
Erik Krogh Kristensen
|
62dfd1fa7d
|
improve the markdown-it model
|
2021-04-20 15:23:03 +02:00 |
|
Erik Krogh Kristensen
|
7046f1a902
|
add taint-step for markdown-it when the HTML flag is set
|
2021-04-20 14:39:54 +02:00 |
|
Asger Feldthaus
|
f8d428cb2d
|
JS: Use function-forwarding steps when tracking rate limiters
|
2021-04-20 13:00:42 +01:00 |
|
Asger Feldthaus
|
581f4ed757
|
JS: Generalize handling of route handler wrapper functions
|
2021-04-20 12:46:40 +01:00 |
|
Asger Feldthaus
|
d2fad180f8
|
JS: Add test
|
2021-04-12 15:07:45 +01:00 |
|
Erik Krogh Kristensen
|
172d6139e2
|
support all ClientRequests in js/disabling-certificate-validation
|
2021-04-12 15:06:10 +02:00 |
|
Erik Krogh Kristensen
|
17c4bbbc4e
|
allow parameters that end with "Command" in js/shell-command-constructed-from-input
|
2021-04-12 09:57:40 +02:00 |
|
CodeQL CI
|
be2fe6e171
|
Merge pull request #5630 from erik-krogh/urlStep
Approved by esbena
|
2021-04-09 07:05:43 -07:00 |
|
Erik Krogh Kristensen
|
30ba69d991
|
treat "files" in a package.json as main modules, if "main" is not present
|
2021-04-08 14:42:12 +02:00 |
|
Erik Krogh Kristensen
|
99dd5330c2
|
add taint-step for URL construction in js/request-forgery
|
2021-04-08 11:10:33 +02:00 |
|
CodeQL CI
|
a9527fd913
|
Merge pull request #5621 from erik-krogh/shellSink
Approved by esbena
|
2021-04-08 09:47:45 +01:00 |
|
CodeQL CI
|
f0491af64c
|
Merge pull request #5529 from erik-krogh/socketInput
Approved by esbena
|
2021-04-07 15:03:13 +01:00 |
|
Asger F
|
0c724a8427
|
Merge pull request #5304 from asgerf/js/non-alert-data
JS: Implement new metric queries for line counting
|
2021-04-07 14:52:51 +01:00 |
|
Erik Krogh Kristensen
|
365b4d722d
|
backtrack string-concatenations from shell-execution sinks
|
2021-04-07 15:34:54 +02:00 |
|
CodeQL CI
|
073a43ce74
|
Merge pull request #5606 from erik-krogh/shellInput
Approved by esbena
|
2021-04-07 14:30:31 +01:00 |
|
Erik Krogh Kristensen
|
c9f54ea1ad
|
update expected output
|
2021-04-07 12:37:17 +00:00 |
|
CodeQL CI
|
fd4e8f8282
|
Merge pull request #5526 from erik-krogh/quotedShell
Approved by esbena
|
2021-04-07 08:39:01 +01:00 |
|
CodeQL CI
|
61880ba90a
|
Merge pull request #5530 from erik-krogh/moreFS
Approved by esbena
|
2021-04-07 08:37:23 +01:00 |
|
Erik Krogh Kristensen
|
41b89669a9
|
add joined paths as a sink to js/shell-command-constructed-from-input
|
2021-04-06 12:14:00 +02:00 |
|
Erik Krogh Kristensen
|
c194598d37
|
recognize headers/url from the HTTP request to a server WebSocket.
|
2021-04-06 10:11:27 +02:00 |
|
CodeQL CI
|
6cceb73807
|
Merge pull request #5553 from asgerf/js/pg-promise
Approved by esbena
|
2021-03-30 11:28:24 +01:00 |
|
Asger Feldthaus
|
67ad6d9a0f
|
JS: Update test output
|
2021-03-29 15:30:29 +01:00 |
|
Asger Feldthaus
|
49ca88957c
|
JS: Use types
|
2021-03-29 12:25:15 +01:00 |
|
Asger Feldthaus
|
603843e698
|
JS: Add task tests
|
2021-03-29 12:05:47 +01:00 |
|
Asger Feldthaus
|
149af57eac
|
JS: Add model of pg-promise
|
2021-03-29 11:25:28 +01:00 |
|
CodeQL CI
|
f584ff9acf
|
Merge pull request #5533 from asgerf/js/fix-query-metadata
Approved by esbena
|
2021-03-26 11:09:54 +00:00 |
|
Asger Feldthaus
|
446ad5ec9e
|
JS: Remove code duplication library
|
2021-03-25 15:20:59 +00:00 |
|
Erik Krogh Kristensen
|
3d49b8cb91
|
consider quoted string concatenations as sanitizers for js/shell-command-injection-from-environment
|
2021-03-25 15:17:02 +01:00 |
|
Erik Krogh Kristensen
|
3b82452d76
|
detect fs modules that pass through a reduce call
|
2021-03-25 14:47:43 +01:00 |
|
Erik Krogh Kristensen
|
77ba7b473d
|
Merge branch 'main' into topPack
|
2021-03-25 11:52:58 +01:00 |
|
Erik Krogh Kristensen
|
3b6b40489f
|
Merge branch 'main' into topPack
|
2021-03-25 09:58:15 +01:00 |
|
Erik Krogh Kristensen
|
c146b27c1a
|
Merge branch 'main' into shellTrue
|
2021-03-24 20:09:23 +01:00 |
|
CodeQL CI
|
8ff9c98d26
|
Merge pull request #5449 from erik-krogh/asExec
Approved by esbena
|
2021-03-24 19:04:30 +00:00 |
|
Asger Feldthaus
|
405c1f3fc7
|
JS: Update test suite
|
2021-03-19 16:45:31 +00:00 |
|
Asger Feldthaus
|
6ca425f033
|
JS: Implement new metric queries for line counting
|
2021-03-19 16:34:29 +00:00 |
|
Erik Krogh Kristensen
|
84e9229386
|
Merge branch 'main' into koa
|
2021-03-19 16:56:15 +01:00 |
|
Erik Krogh Kristensen
|
8949b9eb0a
|
add shell interpreted arrays as sinks for js/shell-command-constructed-from-input
|
2021-03-19 15:59:06 +01:00 |
|
CodeQL CI
|
3b117f5218
|
Merge pull request #5419 from erik-krogh/forgery
Approved by asgerf
|
2021-03-19 12:56:53 +00:00 |
|
CodeQL CI
|
fc7f19f900
|
Merge pull request #5433 from erik-krogh/clientSocket
Approved by esbena
|
2021-03-19 02:12:19 -07:00 |
|
Erik Krogh Kristensen
|
d489d63b8e
|
recognize object transformations in module.exports when looking for library inputs
|
2021-03-18 20:54:33 +01:00 |
|
Erik Krogh Kristensen
|
28ad667578
|
add model for async-execute
|
2021-03-18 19:40:46 +01:00 |
|
Erik Krogh Kristensen
|
58617c5c59
|
recognize client websockets as ClientRequests
|
2021-03-18 19:08:39 +01:00 |
|
Erik Krogh Kristensen
|
67a5831ac0
|
update expected output
|
2021-03-18 13:59:44 +01:00 |
|
Asger Feldthaus
|
e30fa89405
|
JS: Update more test expectations
|
2021-03-18 10:04:39 +00:00 |
|
Erik Krogh Kristensen
|
3995ff322d
|
add models for koa-route and koa-router
|
2021-03-17 19:17:20 +01:00 |
|
Asger Feldthaus
|
9cfbb90591
|
JS: Add test case for insufficient replace-sanitizer
|
2021-03-17 15:20:40 +00:00 |
|
CodeQL CI
|
d95b295e52
|
Merge pull request #5400 from erik-krogh/replaceCallbacks
Approved by asgerf
|
2021-03-17 06:42:34 -07:00 |
|