semmle-qlci
|
fe0c5a9ea6
|
Merge pull request #3892 from asger-semmle/js/redirect-starts-with-sanitizer
Approved by esbena
|
2020-07-06 17:04:30 +01:00 |
|
semmle-qlci
|
6d80445f24
|
Merge pull request #3851 from erik-krogh/queryStuff
Approved by esbena
|
2020-07-06 14:40:41 +01:00 |
|
Erik Krogh Kristensen
|
9a944625d1
|
autoformat
|
2020-07-06 15:17:15 +02:00 |
|
semmle-qlci
|
13c3513d76
|
Merge pull request #3905 from erik-krogh/unsafeShellTypo
Approved by esbena
|
2020-07-06 11:41:56 +01:00 |
|
semmle-qlci
|
73d606d2c3
|
Merge pull request #3844 from github/esbena-patch-3
Approved by erik-krogh
|
2020-07-06 09:47:59 +01:00 |
|
Erik Krogh Kristensen
|
8585312271
|
fix typo in js/shell-command-constructed-from-input
|
2020-07-06 10:33:49 +02:00 |
|
Asger Feldthaus
|
b5104ae42d
|
JS: Add StartsWith sanitizer
|
2020-07-03 14:46:07 +01:00 |
|
Erik Krogh Kristensen
|
078b6a8df2
|
autoformat
|
2020-07-03 00:21:55 +02:00 |
|
Erik Krogh Kristensen
|
261821b32c
|
Merge remote-tracking branch 'upstream/master' into queryStuff
|
2020-07-02 16:08:05 +02:00 |
|
semmle-qlci
|
b5c8f2238b
|
Merge pull request #3805 from esbena/js/seal-freeze-flow
Approved by asgerf
|
2020-07-02 13:54:54 +01:00 |
|
Erik Krogh Kristensen
|
2b0a091921
|
split out type-tracking into two predicates, to avoid catastrophic join-order
|
2020-07-02 14:28:28 +02:00 |
|
semmle-qlci
|
97128b1475
|
Merge pull request #3829 from asger-semmle/js/xss-substr
Approved by erik-krogh
|
2020-07-02 11:58:32 +01:00 |
|
Erik Krogh Kristensen
|
f60a7489b5
|
ignore parents that doesn't have all constant roots when deciding which roots to compute getStringValue for
|
2020-07-02 10:39:41 +02:00 |
|
Erik Krogh Kristensen
|
bbdeca367b
|
use getUnderlyingValue() to find leafs of a string-concat
|
2020-07-02 10:38:02 +02:00 |
|
Erik Krogh Kristensen
|
226e066db8
|
use strictconcat instead of concat
|
2020-07-02 10:12:43 +02:00 |
|
semmle-qlci
|
bfb734e1d7
|
Merge pull request #3832 from asger-semmle/js/typescript-in-html-files3
Approved by erik-krogh
|
2020-07-02 08:30:45 +01:00 |
|
semmle-qlci
|
45ef3ec4a8
|
Merge pull request #3619 from erik-krogh/CWE022-Correctness
Approved by asgerf
|
2020-07-01 20:07:58 +01:00 |
|
Erik Krogh Kristensen
|
6f54bb1613
|
only calculate getStringValue for concatenation roots
|
2020-07-01 20:48:20 +02:00 |
|
semmle-qlci
|
66a6fe7317
|
Merge pull request #3853 from max-schaefer/js/canonical-names
Approved by asgerf
|
2020-07-01 16:08:59 +01:00 |
|
Max Schaefer
|
a6d8073987
|
JavaScript: Make getADefinition and getAnAccess available on all CanonicalNames.
|
2020-07-01 14:42:03 +01:00 |
|
Esben Sparre Andreasen
|
3ca6031ae5
|
JS: rename predicate
|
2020-07-01 15:27:28 +02:00 |
|
Esben Sparre Andreasen
|
75451e349a
|
JS: teach the dataflow library identity functions Object.freeze/seal
|
2020-07-01 15:27:28 +02:00 |
|
Erik Krogh Kristensen
|
8227010463
|
also use new type-tracking in isUserControlledObject
|
2020-07-01 11:32:51 +02:00 |
|
Erik Krogh Kristensen
|
ed48efe5b4
|
recognize access to a query object through function calls
|
2020-06-30 15:52:08 +02:00 |
|
semmle-qlci
|
224289c55f
|
Merge pull request #3845 from max-schaefer/js/walk-sync
Approved by asgerf
|
2020-06-30 14:45:41 +01:00 |
|
semmle-qlci
|
42bca1a3fa
|
Merge pull request #3824 from asger-semmle/js/static-regexp-capture-group-step
Approved by erik-krogh, esbena
|
2020-06-30 13:20:14 +01:00 |
|
semmle-qlci
|
c850938af0
|
Merge pull request #3833 from asger-semmle/js/vue-class-component
Approved by erik-krogh
|
2020-06-30 13:16:42 +01:00 |
|
semmle-qlci
|
15a0297ca2
|
Merge pull request #3834 from asger-semmle/js/vue-classification
Approved by erik-krogh
|
2020-06-30 13:14:25 +01:00 |
|
Max Schaefer
|
62d56a3d7c
|
JavaScript: Fix module name for walk-sync package.
|
2020-06-30 11:57:16 +01:00 |
|
Esben Sparre Andreasen
|
80981ec8f5
|
Update UnsafeHtmlExpansion-transformed.html
|
2020-06-30 12:01:02 +02:00 |
|
Esben Sparre Andreasen
|
c7f67fafd9
|
JS: support additional promisification of the fs-module members
|
2020-06-30 09:10:30 +02:00 |
|
Asger Feldthaus
|
326c7af4eb
|
JS: Fix incorrect classification of Vue files
|
2020-06-29 15:49:07 +01:00 |
|
semmle-qlci
|
da8725aa5c
|
Merge pull request #3823 from dellalibera/js/fancy-log
Approved by erik-krogh
|
2020-06-29 14:46:51 +01:00 |
|
semmle-qlci
|
b3e68ef81c
|
Merge pull request #3806 from erik-krogh/moreDownloads
Approved by asgerf
|
2020-06-29 13:53:10 +01:00 |
|
Asger Feldthaus
|
e46a9dac65
|
JS: Count lines of code correctly
|
2020-06-29 09:59:17 +01:00 |
|
Asger Feldthaus
|
1e5f846168
|
JS: Use StringReplaceCall
|
2020-06-29 09:31:56 +01:00 |
|
Erik Krogh Kristensen
|
27b2c02693
|
remove todo comment
Co-authored-by: Asger F <asgerf@github.com>
|
2020-06-29 09:58:59 +02:00 |
|
Asger F
|
bdb7e3def3
|
Apply suggestions from code review
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2020-06-29 07:55:15 +01:00 |
|
Alessio Della Libera
|
ce32d646dc
|
Update javascript/ql/src/semmle/javascript/frameworks/Logging.qll
Co-authored-by: intrigus-lgtm <60750685+intrigus-lgtm@users.noreply.github.com>
|
2020-06-28 21:58:45 +02:00 |
|
Asger Feldthaus
|
9ca25d5bef
|
JS: Support .hash extraction via a few more methods
|
2020-06-28 01:38:59 +01:00 |
|
Asger Feldthaus
|
19db418395
|
JS: Add missing store step in Xss query
|
2020-06-28 01:26:11 +01:00 |
|
Asger Feldthaus
|
84d21074e5
|
JS: Support Vue class components
|
2020-06-27 21:24:46 +01:00 |
|
Asger Feldthaus
|
ac5b9cd168
|
JS: Autoformat
|
2020-06-26 23:15:04 +01:00 |
|
ubuntu
|
9135bbd5c8
|
JS: model fancy-log (and recognize the 'dir' log level)
|
2020-06-26 21:33:52 +02:00 |
|
Asger Feldthaus
|
6707e3424d
|
JS: Prevent bad join ordering
|
2020-06-26 20:21:56 +01:00 |
|
Asger Feldthaus
|
06dd3ab2ca
|
JS: Propagate into RegExp.$x
|
2020-06-26 18:58:43 +01:00 |
|
semmle-qlci
|
3aefb7fad9
|
Merge pull request #3613 from erik-krogh/Reassigned
Approved by asgerf
|
2020-06-26 17:05:45 +01:00 |
|
semmle-qlci
|
b015c735d0
|
Merge pull request #3809 from max-schaefer/util-deprecate
Approved by asgerf
|
2020-06-26 14:20:14 +01:00 |
|
Erik Krogh Kristensen
|
0b050204ad
|
add missing dot in qldoc
|
2020-06-26 15:07:12 +02:00 |
|
Erik Krogh Kristensen
|
e4fe236d37
|
autoformat
|
2020-06-26 13:59:06 +02:00 |
|