Asger Feldthaus
|
cf78475799
|
JS: Only extract included files with a given tsconfig
|
2020-06-25 15:38:19 +01:00 |
|
Asger Feldthaus
|
6ff81377d5
|
JS: Also sort files in legacy extractor
|
2020-06-25 15:38:18 +01:00 |
|
Asger Feldthaus
|
6d15397fdc
|
JS: Ensure we never write outside the scratch dir
|
2020-06-25 15:38:18 +01:00 |
|
Asger Feldthaus
|
ba5d6bb2e9
|
JS: Actually set fields
|
2020-06-25 15:38:18 +01:00 |
|
Asger Feldthaus
|
dceb211021
|
JS: Pass source root to Node.js process
|
2020-06-25 15:38:18 +01:00 |
|
Asger Feldthaus
|
aaf141782f
|
JS: Fix source root
|
2020-06-25 15:38:17 +01:00 |
|
Asger Feldthaus
|
cb0a2498b0
|
JS: Sort files
|
2020-06-25 15:38:17 +01:00 |
|
semmle-qlci
|
cf0cd00458
|
Merge pull request #3627 from asger-semmle/js/unneeded-defensive-return
Approved by erik-krogh
|
2020-06-25 15:28:57 +01:00 |
|
semmle-qlci
|
c39dce4d66
|
Merge pull request #3781 from asger-semmle/js/deprecate-type-member-lookup
Approved by erik-krogh
|
2020-06-25 14:56:17 +01:00 |
|
Erik Krogh Kristensen
|
c3b52fadcc
|
add missing qldoc
|
2020-06-25 15:54:36 +02:00 |
|
Erik Krogh Kristensen
|
09d969a8ad
|
recognize sensitive files by file-system writes
|
2020-06-25 15:19:42 +02:00 |
|
Erik Krogh Kristensen
|
8f5a3e9f4f
|
add support for getASavePath() to js/insecure-download
|
2020-06-25 15:18:31 +02:00 |
|
Erik Krogh Kristensen
|
dafca8fd81
|
introduce flow-labels to js/insecure-download
|
2020-06-25 15:17:57 +02:00 |
|
Erik Krogh Kristensen
|
9bdedb3f48
|
introduce getASavePath to ClientRequest
|
2020-06-25 15:17:19 +02:00 |
|
Asger Feldthaus
|
f9b796231b
|
JS: Add regression tests
|
2020-06-25 11:10:27 +01:00 |
|
Esben Sparre Andreasen
|
4bfce4b8a3
|
JS: model npmlog (and recognize the "verbose" log level)
|
2020-06-25 12:06:51 +02:00 |
|
semmle-qlci
|
b24fba8df0
|
Merge pull request #3734 from dellalibera/loginjection
Approved by esbena
|
2020-06-25 11:06:25 +01:00 |
|
Asger Feldthaus
|
ea3560fe07
|
JS: Ignore document.all checks explicitly
|
2020-06-25 11:03:06 +01:00 |
|
Asger Feldthaus
|
b867512db4
|
JS: Update test
|
2020-06-25 11:01:10 +01:00 |
|
Erik Krogh Kristensen
|
2d7feb794f
|
Refactor Promises.qll to use PreCallGraphStep
|
2020-06-25 10:41:08 +02:00 |
|
Asger F
|
090a685d86
|
Merge pull request #3751 from toufik-airane/master
[javascript] CWE-347: JWT Missing Secret Or Public Key Verification
|
2020-06-24 21:09:41 +01:00 |
|
ubuntu
|
d9a0dc0982
|
Remove check for console().getAMethodCall
|
2020-06-24 19:31:23 +02:00 |
|
ubuntu
|
65eba0272d
|
Merge remote-tracking branch 'upstream/master' into loginjection
|
2020-06-24 19:15:27 +02:00 |
|
semmle-qlci
|
daeb13d9fd
|
Merge pull request #3779 from asger-semmle/js/metric-queries
Approved by esbena
|
2020-06-24 15:37:03 +01:00 |
|
Asger Feldthaus
|
42f32bf76c
|
JS: Recognize calls to .item and .namedItem
|
2020-06-24 15:11:18 +01:00 |
|
semmle-qlci
|
696d19cb14
|
Merge pull request #3773 from erik-krogh/guardedCrypto
Approved by asgerf
|
2020-06-24 13:04:04 +01:00 |
|
semmle-qlci
|
a723ac0d8e
|
Merge pull request #3767 from esbena/js/console-member-calls
Approved by erik-krogh
|
2020-06-24 08:03:49 +01:00 |
|
Asger Feldthaus
|
d15c98d18c
|
JS: Add more metrics
|
2020-06-24 08:03:24 +01:00 |
|
Asger Feldthaus
|
63d48bfe5c
|
JS: Move IgnoredFile to MetaMetrics
|
2020-06-23 17:08:09 +01:00 |
|
Asger Feldthaus
|
35bdb4127e
|
JS: Add TypedExprs metric
|
2020-06-23 17:05:58 +01:00 |
|
Erik Krogh Kristensen
|
3f8881a334
|
don't report insecure randomness when the insecure random is just a fallback
|
2020-06-23 15:53:19 +02:00 |
|
semmle-qlci
|
0d61443915
|
Merge pull request #3753 from asger-semmle/js/xss-dom-exception-rephrasing
Approved by erik-krogh
|
2020-06-23 13:01:41 +01:00 |
|
Asger F
|
552b7ad3ca
|
Merge pull request #3765 from asger-semmle/js-team-sprint-merge2
JS: Merge js-team-sprint
|
2020-06-23 12:58:27 +01:00 |
|
semmle-qlci
|
a5a3573a3e
|
Merge pull request #3757 from asger-semmle/js/unused-npm-dependencies
Approved by erik-krogh
|
2020-06-23 12:56:45 +01:00 |
|
Asger Feldthaus
|
4f67cc269b
|
JS: Reduce ExpansiveTypes test
|
2020-06-23 11:44:07 +01:00 |
|
Asger Feldthaus
|
234f968294
|
JS: Deprecate property lookup on types
|
2020-06-23 11:42:28 +01:00 |
|
Toufik Airane
|
27f91b36b0
|
Update javascript/ql/src/experimental/Security/CWE-347/JWTMissingSecretOrPublicKeyVerification.ql
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2020-06-23 12:28:21 +02:00 |
|
toufik-airane
|
37f44d98ce
|
fix minor issues
|
2020-06-23 12:28:03 +02:00 |
|
Esben Sparre Andreasen
|
2d32ee7448
|
JS: support member calls of console
|
2020-06-23 10:46:01 +02:00 |
|
Asger Feldthaus
|
b4f75ef414
|
Merge branch 'master' into js-team-sprint-merge2
|
2020-06-23 00:18:09 +01:00 |
|
Asger F
|
ca06f6dfb4
|
Merge branch 'js-team-sprint' into js/insecure-http-options
|
2020-06-23 00:16:02 +01:00 |
|
toufik-airane
|
f7cbc8a8d4
|
Enhance query ouput
- add valuable text to assess the query results
- add an example of the output
|
2020-06-22 22:34:06 +02:00 |
|
toufik-airane
|
0f8879716f
|
rewrite description
|
2020-06-22 21:57:58 +02:00 |
|
Alessio Della Libera
|
a759905a5c
|
Update javascript/ql/src/experimental/Security/CWE-117/LogInjection.qll
Co-authored-by: Esben Sparre Andreasen <esbena@github.com>
|
2020-06-22 20:37:38 +02:00 |
|
toufik-airane
|
364f0ca734
|
rewrite description
|
2020-06-22 20:11:58 +02:00 |
|
toufik-airane
|
ac8991b192
|
remove JWTMissingSecretOrPublicKeyVerification.qll
|
2020-06-22 20:09:48 +02:00 |
|
toufik-airane
|
d9ecb7d762
|
rewrite help
|
2020-06-22 20:06:17 +02:00 |
|
toufik-airane
|
d65b7be32b
|
rewrite help
|
2020-06-22 20:00:52 +02:00 |
|
Toufik Airane
|
bb7ba50e23
|
Apply suggestions from code review
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2020-06-22 19:27:36 +02:00 |
|
Asger Feldthaus
|
1efd71a681
|
JS: Sort security suite
|
2020-06-22 16:40:55 +01:00 |
|