Asger Feldthaus
|
16e3681fd3
|
JS: Update RegExpInjection test case
|
2021-06-22 12:00:04 +02:00 |
|
Erik Krogh Kristensen
|
33641c84f6
|
recognize sanitizing string replace call for regexp-injection
|
2021-05-14 11:58:27 +02:00 |
|
Erik Krogh Kristensen
|
ab53f3b380
|
add array.filter() as a taint-step
|
2021-05-05 12:03:14 +02:00 |
|
Asger Feldthaus
|
aa1c8c041e
|
JS: Exclude client-side sources from RegExpInjection
|
2021-03-16 13:28:11 +00:00 |
|
Esben Sparre Andreasen
|
3015dcd310
|
JS: reformulate js/server-crash. Support promises and shorter paths.
|
2021-01-19 09:08:52 +01:00 |
|
Esben Sparre Andreasen
|
1bc7d68a50
|
Update javascript/ql/test/query-tests/Security/CWE-730/server-crash.js
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2021-01-13 14:49:42 +01:00 |
|
Esben Sparre Andreasen
|
d591c519a8
|
JS: reformulate js/server-crash as a path problem
|
2021-01-13 00:08:28 +01:00 |
|
Esben Sparre Andreasen
|
2dbd762bd9
|
JS: reintroduce reverted js/server-crash
This reverts commit 0a8d15ccc4.
|
2021-01-11 14:13:41 +01:00 |
|
Erik Krogh Kristensen
|
0d64a0f2c8
|
update consistency comment for CWE-730
|
2020-07-08 10:07:34 +02:00 |
|
Erik Krogh Kristensen
|
15d74b7d03
|
remove FP from js/regexpinjection where no regexp was constructed
|
2019-12-19 10:47:03 +01:00 |
|
Max Schaefer
|
b42026a90a
|
JavaScript: Update expected output.
|
2019-10-29 15:36:24 +00:00 |
|
Max Schaefer
|
dc1d1c2f22
|
JavaScript: Update expected output.
|
2019-10-29 15:30:06 +00:00 |
|
Max Schaefer
|
6964945c74
|
JavaScript: Restrict edges to only contain nodes.
|
2019-10-29 15:03:52 +00:00 |
|
Asger F
|
50a77ea843
|
JS: update test expectations
|
2019-03-06 08:41:03 +00:00 |
|
Max Schaefer
|
9221b62ded
|
JavaScript: Update expectd test output for security path queries to include nodes and edges query predicates.
|
2018-11-14 09:32:31 +00:00 |
|
Esben Sparre Andreasen
|
3d3b7b0254
|
JS: fix typo in test case
|
2018-09-06 22:54:07 +02:00 |
|
Esben Sparre Andreasen
|
b9d825b379
|
JS: better matching of String.prototype.search in js/regex-injection
|
2018-09-05 08:35:00 +02:00 |
|
Pavel Avgustinov
|
b55526aa58
|
QL code and tests for C#/C++/JavaScript.
|
2018-08-02 17:53:23 +01:00 |
|