Erik Krogh Kristensen
|
34fd0d89f5
|
finding the minimum that is not an FP - instead of finding the minimum and then checking if it was an FP. And detecting more FPs by finding when a witness pass through the accept state
|
2020-11-08 23:24:27 +01:00 |
|
Erik Krogh Kristensen
|
ac514b1739
|
remove false positives where the analysis would wrongly conclude that the accept state could not be reached
|
2020-11-08 23:24:03 +01:00 |
|
Erik Krogh Kristensen
|
a5e75f53ff
|
add support for escape char classes inside char classes
|
2020-11-08 23:22:49 +01:00 |
|
Erik Krogh Kristensen
|
0063cb140c
|
add support for \W, \S, \D
|
2020-11-08 23:16:56 +01:00 |
|
Erik Krogh Kristensen
|
2dd8b6ffef
|
support \f and \v in the \s class
|
2020-11-08 23:16:56 +01:00 |
|
Erik Krogh Kristensen
|
68fe03060d
|
support \d \s and \w in ReDoS.ql
|
2020-11-08 23:16:56 +01:00 |
|
Erik Krogh Kristensen
|
fa54ad1a5e
|
refactor character class implementation in ReDoS.ql - preparing support for RegExpCharacterClassEscape
|
2020-11-08 23:16:55 +01:00 |
|
Erik Krogh Kristensen
|
a09ffd5cda
|
expand getAOverlapBetweenCharacterClasses to support overlap between more char classes
|
2020-11-08 23:16:37 +01:00 |
|
Erik Krogh Kristensen
|
82252c0f1c
|
detect redos between charclass and inverted charclass
|
2020-11-08 23:16:34 +01:00 |
|
Erik Krogh Kristensen
|
16473fc2a4
|
matching a inverted char class with a char
|
2020-11-06 10:18:57 +01:00 |
|
Erik Krogh Kristensen
|
804aaf36f0
|
support inverted char class and dot
|
2020-11-06 10:18:57 +01:00 |
|
Erik Krogh Kristensen
|
64d680e2d3
|
support that an inverted char class can intersect with itself
|
2020-11-06 10:18:57 +01:00 |
|
Erik Krogh Kristensen
|
321cf09bd8
|
add redos support for the simplest possible inverted char class
|
2020-11-06 10:18:57 +01:00 |
|
Asger Feldthaus
|
24714c41be
|
JS: Update test output after rebase
|
2020-11-06 09:14:03 +00:00 |
|
Asger Feldthaus
|
7bf21d80b2
|
JS: Shift line numbers in test file
|
2020-11-06 09:13:52 +00:00 |
|
Asger Feldthaus
|
9418c6c8fe
|
JS: Add support for dateformat package
|
2020-11-06 09:13:52 +00:00 |
|
Asger Feldthaus
|
790526b529
|
JS: Some fixes and address review comments
|
2020-11-06 09:06:20 +00:00 |
|
Asger Feldthaus
|
8a3fba05e9
|
JS: Add steps through date-formatting functions
|
2020-11-06 09:06:18 +00:00 |
|
CodeQL CI
|
a908e5938e
|
Merge pull request #4574 from erik-krogh/jsdom
Approved by asgerf
|
2020-11-05 22:13:39 +00:00 |
|
Erik Krogh Kristensen
|
e124ba66b4
|
moving jsdom sink to js/xss
|
2020-11-05 16:10:33 +01:00 |
|
CodeQL CI
|
c85f817cee
|
Merge pull request #4579 from erik-krogh/redos
Approved by asgerf
|
2020-11-05 08:38:44 +00:00 |
|
Erik Krogh Kristensen
|
e16fa0668a
|
update expected output
|
2020-11-04 18:24:31 +01:00 |
|
Erik Krogh Kristensen
|
b02004430c
|
prune results that end with newline, where the input cannot contain newlines
|
2020-11-03 14:48:39 +01:00 |
|
Erik Krogh Kristensen
|
120faf9d1a
|
add a code injection sink for JSDOM when "runScripts" is set to "dangerously"
|
2020-11-03 14:29:00 +01:00 |
|
Erik Krogh Kristensen
|
e6e4a485c8
|
add JSDOM.fromUrl() as a request forgery sink
|
2020-11-02 17:05:56 +01:00 |
|
CodeQL CI
|
4a59e69722
|
Merge pull request #4564 from asgerf/js/react-hooks
Approved by esbena
|
2020-10-30 21:00:31 +00:00 |
|
Erik Krogh Kristensen
|
ebc4856456
|
detect more expensive regexps in js/polynomial-redos
|
2020-10-30 09:52:13 +01:00 |
|
CodeQL CI
|
7856e784e1
|
Merge pull request #4566 from asgerf/js/classnames
Approved by erik-krogh
|
2020-10-29 11:00:06 +00:00 |
|
Asger Feldthaus
|
469767d279
|
JS: Fix test output
|
2020-10-28 17:00:05 +00:00 |
|
Asger Feldthaus
|
f99db23e7b
|
JS: Add test and fix for contextType
|
2020-10-28 16:23:36 +00:00 |
|
Asger Feldthaus
|
3d86e855f3
|
JS: Add model of classnames and clsx
|
2020-10-28 13:56:35 +00:00 |
|
Asger Feldthaus
|
d116b424f4
|
JS: Add model of react hooks and react-router
|
2020-10-28 11:57:11 +00:00 |
|
Erik Krogh Kristensen
|
bce06d3194
|
add test that promisify is not imprecise
|
2020-10-28 11:59:03 +01:00 |
|
Erik Krogh Kristensen
|
2e514c4d7b
|
add model for Node Redis
|
2020-10-28 09:52:54 +01:00 |
|
CodeQL CI
|
da58306f2d
|
Merge pull request #4506 from asgerf/js/separate-jquery-config
Approved by esbena
|
2020-10-21 03:13:42 -07:00 |
|
CodeQL CI
|
897d8de65a
|
Merge pull request #4523 from erik-krogh/optionalPromise
Approved by asgerf
|
2020-10-21 00:34:12 -07:00 |
|
Erik Krogh Kristensen
|
bdbc8f5c91
|
add support for OptionalUse in js/missing-await
|
2020-10-20 16:52:57 +02:00 |
|
CodeQL CI
|
7ea8652f49
|
Merge pull request #4521 from erik-krogh/moreMiddle
Approved by asgerf
|
2020-10-20 07:14:14 -07:00 |
|
Erik Krogh Kristensen
|
e061c6a006
|
add support for more custom CSRF checking middlewares
|
2020-10-20 15:16:14 +02:00 |
|
CodeQL CI
|
d2282fc474
|
Merge pull request #4517 from erik-krogh/logAssign
Approved by esbena
|
2020-10-20 05:24:49 -07:00 |
|
Asger Feldthaus
|
8779b7c1ce
|
JS: Update expected output after rebase
|
2020-10-20 11:10:30 +01:00 |
|
Asger Feldthaus
|
28a73c1e18
|
JS: Add test case
|
2020-10-20 10:53:15 +01:00 |
|
Asger Feldthaus
|
6aac353777
|
JS: Update test output
|
2020-10-20 10:53:12 +01:00 |
|
Asger Feldthaus
|
50a015c73e
|
JS: Move $() sink into separate dataflow config
|
2020-10-20 10:52:33 +01:00 |
|
CodeQL CI
|
4cc7138784
|
Merge pull request #4507 from erik-krogh/template
Approved by asgerf
|
2020-10-20 02:45:00 -07:00 |
|
Erik Krogh Kristensen
|
7d87699e42
|
add test for modern compound assignment in js/implicit-operand-conversion
|
2020-10-20 10:50:20 +02:00 |
|
CodeQL CI
|
4c5ecb4093
|
Merge pull request #4478 from erik-krogh/homegrownCsrf
Approved by asgerf
|
2020-10-19 11:04:10 -07:00 |
|
CodeQL CI
|
5ead4244fe
|
Merge pull request #4450 from asgerf/js/angular
Approved by erik-krogh
|
2020-10-19 07:25:59 -07:00 |
|
Erik Krogh Kristensen
|
ce95676130
|
add express.csrf as an CSRF protecting middleware
|
2020-10-19 15:39:02 +02:00 |
|
CodeQL CI
|
2e52cbeb4a
|
Merge pull request #4499 from max-schaefer/js/module_compile
Approved by asgerf
|
2020-10-19 03:06:21 -07:00 |
|