Erik Krogh Kristensen
|
0f85a52f09
|
Merge pull request #7773 from erik-krogh/CWE-367
JS: add a js/file-system-race query
|
2022-02-01 15:36:13 +01:00 |
|
Erik Krogh Kristensen
|
e6c90670e6
|
Merge pull request #7740 from erik-krogh/CWE-347
JS: promote the js/jwt-missing-verification query out of experimental
|
2022-02-01 13:10:35 +01:00 |
|
Erik Krogh Kristensen
|
7b925604df
|
update expected output
|
2022-01-28 12:21:33 +01:00 |
|
Erik Krogh Kristensen
|
7aa59ca233
|
Merge pull request #7633 from erik-krogh/CWE-300
JS: add js/http-dependency query
|
2022-01-28 12:10:14 +01:00 |
|
Erik Krogh Kristensen
|
bf9bcc9600
|
add a js/file-system-race query
|
2022-01-28 09:41:12 +01:00 |
|
Stephan Brandauer
|
b7690e5e6b
|
Merge pull request #7734 from kaeluka/js-add-node-prefix-to-module-import
js: add support for the 'node:' prefix for importing internal modules
|
2022-01-26 10:15:08 +01:00 |
|
Erik Krogh Kristensen
|
de633940fe
|
promote the js/jwt-missing-verification query out of exeprimental
|
2022-01-26 09:35:54 +01:00 |
|
Stephan Brandauer
|
4ee290acd3
|
update test for 'node:' prefix
|
2022-01-25 14:25:44 +01:00 |
|
Stephan Brandauer
|
20ea825e4a
|
test for 'node:' prefix for importing node modules
|
2022-01-25 13:43:16 +01:00 |
|
Erik Krogh Kristensen
|
cc527bdecd
|
Merge pull request #7721 from erik-krogh/CWE-1275
JS: add a js/samesite-none-cookie cookie
|
2022-01-25 13:28:08 +01:00 |
|
Erik Krogh Kristensen
|
d4bac887cf
|
add a js/samesite-none-cookie cookie
|
2022-01-24 21:39:41 +01:00 |
|
Erik Krogh Kristensen
|
ef2eacebce
|
add a js/empty-password-in-configuration-file query
|
2022-01-19 10:48:45 +01:00 |
|
Erik Krogh Kristensen
|
b7a0b8765e
|
add js/http-dependency query
|
2022-01-19 10:05:39 +01:00 |
|
Asger Feldthaus
|
708408a458
|
JS: Recognize "sql" option as a query string
|
2022-01-13 13:04:41 +01:00 |
|
CodeQL CI
|
39ec7132af
|
Merge pull request #7049 from asgerf/js/routing-trees
Approved by erik-krogh
|
2021-12-17 12:26:38 +00:00 |
|
CodeQL CI
|
acbf7913b2
|
Merge pull request #7408 from asgerf/js/trusted-types-sinks
Approved by esbena
|
2021-12-16 08:59:51 +00:00 |
|
Asger Feldthaus
|
4d85799fc7
|
JS: Add test for fastify-rate-limit
|
2021-12-15 16:18:22 +01:00 |
|
Asger Feldthaus
|
615b2ec539
|
JS: Fix handling of fastify-plugin
|
2021-12-15 16:04:46 +01:00 |
|
Asger Feldthaus
|
7e947b2a65
|
JS: Use return value of trusted type policy callback as a sink
|
2021-12-14 13:28:46 +01:00 |
|
Esben Sparre Andreasen
|
c66d29998e
|
update test output for additional DatabaseAccesses
|
2021-12-13 13:42:28 +01:00 |
|
Esben Sparre Andreasen
|
9ffc02944d
|
add file write model for express-fileupload mv
|
2021-12-10 15:05:34 +01:00 |
|
Asger Feldthaus
|
da8e67b7ee
|
JS: Use routing trees to detect deeply tainted req.body
|
2021-12-07 10:46:18 +01:00 |
|
Asger Feldthaus
|
7492293c5b
|
JS: Add test with route handler indirection
|
2021-12-07 10:46:18 +01:00 |
|
Asger Feldthaus
|
3cbe94ac0a
|
JS: Add consistency checks to TemplateObjectInjection test
|
2021-12-07 10:46:18 +01:00 |
|
Asger Feldthaus
|
64db70f3ac
|
JS: Add explicit body-parsers to TemplateObjectInjection test
|
2021-12-07 10:46:18 +01:00 |
|
Asger Feldthaus
|
8af430d40f
|
JS: Shift line numbers in TemplateObjectInjection test
|
2021-12-07 10:46:17 +01:00 |
|
Asger Feldthaus
|
b73219392b
|
JS: Improve precision of missing CSRF middleware
|
2021-12-07 10:46:17 +01:00 |
|
Asger Feldthaus
|
d0e94e655d
|
JS: Exclude error handling from auth calls
|
2021-12-07 10:46:17 +01:00 |
|
Asger Feldthaus
|
71820569e1
|
JS: Instantiate for Fastify
|
2021-12-07 10:46:15 +01:00 |
|
Asger Feldthaus
|
5269933461
|
JS: Port missing rate limiting query
|
2021-12-07 10:44:19 +01:00 |
|
Asger Feldthaus
|
389a3c9073
|
JS: Port CSRF query
|
2021-12-07 10:43:06 +01:00 |
|
Erik Krogh Kristensen
|
1cca377e7d
|
Merge pull request #6561 from erik-krogh/htmlReg
JS/Py/Ruby: add a bad-tag-filter query
|
2021-11-18 09:39:13 +01:00 |
|
Erik Krogh Kristensen
|
a7cd097ca2
|
Merge pull request #6756 from erik-krogh/extractBigReg
JS: extract regexp literals for string concatenations
|
2021-11-16 13:33:21 +01:00 |
|
Erik Krogh Kristensen
|
12c24c07df
|
improve the got model
|
2021-11-15 21:52:12 +01:00 |
|
Erik Krogh Kristensen
|
0023b885f5
|
update expected output
|
2021-11-15 13:50:12 +01:00 |
|
Erik Krogh Kristensen
|
eef7709982
|
Merge pull request #7057 from erik-krogh/cwe598
JS: add js/sensitive-get-query query
|
2021-11-12 16:03:21 +01:00 |
|
Erik Krogh Kristensen
|
e09c12430d
|
Merge pull request #7105 from erik-krogh/flagJqueryUI
JS: have the aliasPropertyPresenceStep step over extend calls
|
2021-11-11 14:05:11 +01:00 |
|
Erik Krogh Kristensen
|
b513033e0f
|
Merge pull request #7021 from erik-krogh/cwe326
JS: Add insufficient key size query
|
2021-11-11 12:17:04 +01:00 |
|
Erik Krogh Kristensen
|
891694b50a
|
Merge pull request #5908 from erik-krogh/protoLib
JS: Add library input as source to js/prototype-polluting-assignment
|
2021-11-11 12:04:05 +01:00 |
|
Erik Krogh Kristensen
|
140a70f9df
|
Merge pull request #7029 from erik-krogh/cwe384
JS: add js/session-fixation query
|
2021-11-11 11:59:52 +01:00 |
|
Erik Krogh Kristensen
|
5d901ef728
|
move extend aliasing to getAnAliasedSourceNode
|
2021-11-10 18:08:50 +01:00 |
|
Erik Krogh Kristensen
|
2d907f825e
|
have the aliasPropertyPresenceStep step over extend calls
|
2021-11-10 16:26:00 +01:00 |
|
Asger Feldthaus
|
f14f9449ee
|
JS: Use getAMatchedString instead of getConstantString
|
2021-11-08 15:35:35 +01:00 |
|
Asger Feldthaus
|
b3e64f1669
|
JS: Add test
|
2021-11-08 15:32:43 +01:00 |
|
Erik Krogh Kristensen
|
0ab510f543
|
add test that requires flowToExpr
|
2021-11-08 12:25:45 +01:00 |
|
CodeQL CI
|
6f80387ac1
|
Merge pull request #6993 from asgerf/js/tainted-path-regexp-contains-check
Approved by erik-krogh
|
2021-11-08 01:52:28 -08:00 |
|
Erik Krogh Kristensen
|
02f500b9c2
|
Merge branch 'main' into htmlReg
|
2021-11-04 12:58:42 +01:00 |
|
Erik Krogh Kristensen
|
99f5f70345
|
Merge branch 'main' into protoLib
|
2021-11-04 12:53:53 +01:00 |
|
Erik Krogh Kristensen
|
4ba5ae09b0
|
add js/sensitive-get-query query
|
2021-11-04 12:30:44 +01:00 |
|
Erik Krogh Kristensen
|
523c15cd72
|
don't include mode-of-operation into the algorithm names
|
2021-11-03 14:54:50 +01:00 |
|