Erik Krogh Kristensen
|
2dd8b6ffef
|
support \f and \v in the \s class
|
2020-11-08 23:16:56 +01:00 |
|
Erik Krogh Kristensen
|
68fe03060d
|
support \d \s and \w in ReDoS.ql
|
2020-11-08 23:16:56 +01:00 |
|
Erik Krogh Kristensen
|
fa54ad1a5e
|
refactor character class implementation in ReDoS.ql - preparing support for RegExpCharacterClassEscape
|
2020-11-08 23:16:55 +01:00 |
|
Erik Krogh Kristensen
|
a09ffd5cda
|
expand getAOverlapBetweenCharacterClasses to support overlap between more char classes
|
2020-11-08 23:16:37 +01:00 |
|
Erik Krogh Kristensen
|
4ede04f4d1
|
improve performance by pruning based on shared root
|
2020-11-08 23:16:37 +01:00 |
|
Erik Krogh Kristensen
|
82252c0f1c
|
detect redos between charclass and inverted charclass
|
2020-11-08 23:16:34 +01:00 |
|
Asger Feldthaus
|
acb30e73bc
|
JS: More precise handling of default import fallback
|
2020-11-06 12:04:41 +00:00 |
|
Erik Krogh Kristensen
|
16473fc2a4
|
matching a inverted char class with a char
|
2020-11-06 10:18:57 +01:00 |
|
Erik Krogh Kristensen
|
804aaf36f0
|
support inverted char class and dot
|
2020-11-06 10:18:57 +01:00 |
|
Erik Krogh Kristensen
|
64d680e2d3
|
support that an inverted char class can intersect with itself
|
2020-11-06 10:18:57 +01:00 |
|
Erik Krogh Kristensen
|
321cf09bd8
|
add redos support for the simplest possible inverted char class
|
2020-11-06 10:18:57 +01:00 |
|
Erik Krogh Kristensen
|
d04f3df1cd
|
remove rendundant check
|
2020-11-06 10:18:57 +01:00 |
|
Asger Feldthaus
|
9e25bbc4ed
|
JS: Add support for moment-timezone as well
|
2020-11-06 09:13:52 +00:00 |
|
Asger Feldthaus
|
9418c6c8fe
|
JS: Add support for dateformat package
|
2020-11-06 09:13:52 +00:00 |
|
CodeQL CI
|
9f2eb84f2b
|
Merge pull request #4624 from erik-krogh/concatFix
Approved by asgerf
|
2020-11-06 09:11:41 +00:00 |
|
Asger Feldthaus
|
39c8226fba
|
JS: Autoformat
|
2020-11-06 09:06:20 +00:00 |
|
Asger Feldthaus
|
790526b529
|
JS: Some fixes and address review comments
|
2020-11-06 09:06:20 +00:00 |
|
Asger Feldthaus
|
8a3fba05e9
|
JS: Add steps through date-formatting functions
|
2020-11-06 09:06:18 +00:00 |
|
Asger Feldthaus
|
d07e69e529
|
JS: Improve handling of destructuring export declaration
|
2020-11-05 23:51:44 +00:00 |
|
CodeQL CI
|
a908e5938e
|
Merge pull request #4574 from erik-krogh/jsdom
Approved by asgerf
|
2020-11-05 22:13:39 +00:00 |
|
Erik Krogh Kristensen
|
9137759d7c
|
calculate the size of the concatenation before doing the actual concatenation in Expr.qll
|
2020-11-05 22:55:52 +01:00 |
|
Erik Krogh Kristensen
|
e124ba66b4
|
moving jsdom sink to js/xss
|
2020-11-05 16:10:33 +01:00 |
|
CodeQL CI
|
89a808cafe
|
Merge pull request #4552 from erik-krogh/tsImport
Approved by asgerf
|
2020-11-05 09:23:58 +00:00 |
|
CodeQL CI
|
b55f18bffd
|
Merge pull request #4549 from erik-krogh/pruneReturn
Approved by asgerf
|
2020-11-05 09:13:21 +00:00 |
|
CodeQL CI
|
c85f817cee
|
Merge pull request #4579 from erik-krogh/redos
Approved by asgerf
|
2020-11-05 08:38:44 +00:00 |
|
Erik Krogh Kristensen
|
342b6a4f2d
|
Update javascript/ql/src/semmle/javascript/security/performance/SuperlinearBackTracking.qll
Co-authored-by: Asger F <asgerf@github.com>
|
2020-11-04 22:37:56 +01:00 |
|
Erik Krogh Kristensen
|
03c46c9be0
|
autoformat
|
2020-11-04 16:18:24 +01:00 |
|
Erik Krogh Kristensen
|
b02004430c
|
prune results that end with newline, where the input cannot contain newlines
|
2020-11-03 14:48:39 +01:00 |
|
Erik Krogh Kristensen
|
120faf9d1a
|
add a code injection sink for JSDOM when "runScripts" is set to "dangerously"
|
2020-11-03 14:29:00 +01:00 |
|
Erik Krogh Kristensen
|
e6e4a485c8
|
add JSDOM.fromUrl() as a request forgery sink
|
2020-11-02 17:05:56 +01:00 |
|
CodeQL CI
|
4a59e69722
|
Merge pull request #4564 from asgerf/js/react-hooks
Approved by esbena
|
2020-10-30 21:00:31 +00:00 |
|
Asger Feldthaus
|
c7667d372e
|
JS: Address review comments
|
2020-10-30 16:25:30 +00:00 |
|
Asger Feldthaus
|
6ab7846e81
|
JS: Restrict getAContextInput
|
2020-10-30 09:28:06 +00:00 |
|
Erik Krogh Kristensen
|
ebc4856456
|
detect more expensive regexps in js/polynomial-redos
|
2020-10-30 09:52:13 +01:00 |
|
CodeQL CI
|
7856e784e1
|
Merge pull request #4566 from asgerf/js/classnames
Approved by erik-krogh
|
2020-10-29 11:00:06 +00:00 |
|
Asger F
|
581441d585
|
Update javascript/ql/src/semmle/javascript/frameworks/React.qll
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2020-10-28 16:29:15 +00:00 |
|
Asger Feldthaus
|
f99db23e7b
|
JS: Add test and fix for contextType
|
2020-10-28 16:23:36 +00:00 |
|
Asger F
|
056ce38dad
|
Update javascript/ql/src/semmle/javascript/frameworks/Classnames.qll
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2020-10-28 14:35:37 +00:00 |
|
Asger Feldthaus
|
081017ea8a
|
JS: Autoformat
|
2020-10-28 13:58:02 +00:00 |
|
Asger Feldthaus
|
3d86e855f3
|
JS: Add model of classnames and clsx
|
2020-10-28 13:56:35 +00:00 |
|
Asger Feldthaus
|
7ee3846142
|
JS: Add missing qldoc
|
2020-10-28 12:43:48 +00:00 |
|
Asger Feldthaus
|
7a3f0095f6
|
JS: Autoformat
|
2020-10-28 11:57:23 +00:00 |
|
Asger Feldthaus
|
d116b424f4
|
JS: Add model of react hooks and react-router
|
2020-10-28 11:57:11 +00:00 |
|
Asger Feldthaus
|
42c03ab2fd
|
JS: Add flow steps through dynamic imports
|
2020-10-28 11:57:08 +00:00 |
|
Erik Krogh Kristensen
|
75d996a0f9
|
make promisify smaller
|
2020-10-28 11:59:21 +01:00 |
|
Erik Krogh Kristensen
|
c49d5081cc
|
Update javascript/ql/src/semmle/javascript/frameworks/NoSQL.qll
Co-authored-by: Asger F <asgerf@github.com>
|
2020-10-28 11:45:58 +01:00 |
|
Asger Feldthaus
|
a9adb2912a
|
JS: Improve lodash model
|
2020-10-28 10:09:41 +00:00 |
|
Asger Feldthaus
|
9fc5c0bdb8
|
JS: Update ComposedFunctions
|
2020-10-28 10:09:40 +00:00 |
|
Erik Krogh Kristensen
|
2e514c4d7b
|
add model for Node Redis
|
2020-10-28 09:52:54 +01:00 |
|
Asger Feldthaus
|
7345df63c0
|
JS: Include DataFlow::AdditionalFlowStep in TaintSteps metric
|
2020-10-27 08:41:50 +00:00 |
|