Asger F
|
82cee61999
|
JS: Include sink nodes as base-case when resolving types
|
2024-01-11 13:41:21 +01:00 |
|
Erik Krogh Kristensen
|
3000b4b9b3
|
rename PropsTaintStep to PropsFlowStep
Co-authored-by: Asger F <asgerf@github.com>
|
2024-01-10 09:45:29 +01:00 |
|
maikypedia
|
78e7793e01
|
Move to experimental
|
2024-01-09 01:11:58 +01:00 |
|
Sid Shankar
|
e30a0d1e83
|
JS: Report any extracted file as successfully extracted
|
2024-01-08 22:19:33 +00:00 |
|
github-actions[bot]
|
a6c8cc9551
|
Release preparation for version 2.16.0
|
2024-01-08 13:11:26 +00:00 |
|
erik-krogh
|
58dc14d5bb
|
update expected output
|
2024-01-04 11:38:58 +01:00 |
|
erik-krogh
|
a9f2b3fad6
|
promote PropsTaintStep to a PreCallGraphStep
|
2024-01-04 10:45:22 +01:00 |
|
Aditya Sharad
|
b1803d0ac2
|
Merge rc/3.12 into main
|
2023-12-21 16:40:51 -08:00 |
|
erik-krogh
|
fe3e768414
|
update expected output of tests
|
2023-12-20 14:10:36 +01:00 |
|
maikypedia
|
7662b2bd24
|
format
|
2023-12-19 13:23:05 +01:00 |
|
github-actions[bot]
|
8f72b0e4f7
|
Post-release preparation for codeql-cli-2.15.5
|
2023-12-19 10:32:57 +00:00 |
|
Jorge
|
f8cfd698fa
|
Merge branch 'main' into seclab/dotjs
|
2023-12-19 10:44:52 +01:00 |
|
github-actions[bot]
|
19af35b29a
|
Release preparation for version 2.15.5
|
2023-12-18 21:22:44 +00:00 |
|
Jorge
|
b81fbd7669
|
Add change note
|
2023-12-18 12:55:30 +01:00 |
|
Maiky
|
191766a47b
|
Use config.getCorsConfiguration().getOrigin())
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2023-12-18 12:38:39 +01:00 |
|
Maiky
|
4f68f60db2
|
Apply review
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2023-12-18 12:37:05 +01:00 |
|
erik-krogh
|
a694928dd3
|
use the extractor option directly instead
|
2023-12-15 10:39:36 +01:00 |
|
erik-krogh
|
ad4f464850
|
add warnOnImplicitThis
|
2023-12-15 09:55:30 +01:00 |
|
erik-krogh
|
9cc708b122
|
add integration test for the new extractor option to disable type extraction
|
2023-12-15 09:53:13 +01:00 |
|
Remco Vermeulen
|
133a243298
|
Add support for XML attributes in the data flow graph
|
2023-12-14 11:33:53 -08:00 |
|
Tom Hvitved
|
c8b4a215bc
|
Merge pull request #14573 from hvitved/flow-summary-impl-param
Move `FlowSummaryImpl.qll` to `dataflow` pack
|
2023-12-14 12:24:15 +01:00 |
|
Jeroen Ketema
|
99e65df6ce
|
Merge remote-tracking branch 'upstream/rc/3.12' into mb12
|
2023-12-13 15:43:39 +01:00 |
|
Tom Hvitved
|
a46964dfe8
|
Address review comments
|
2023-12-12 13:55:52 +01:00 |
|
amammad
|
102f09aa23
|
extend tests
|
2023-12-10 20:33:00 +01:00 |
|
amammad
|
18d0b28024
|
v1
|
2023-12-10 20:27:21 +01:00 |
|
Tom Hvitved
|
28373e0fdf
|
JS: Adapt to changes in shared code
|
2023-12-10 11:25:43 +01:00 |
|
erik-krogh
|
e8f9e366d5
|
remove redundant imports for JS
|
2023-12-08 16:56:54 +01:00 |
|
maikypedia
|
87cac2a4e3
|
Express Argument has to be Cors
|
2023-12-07 23:01:41 +01:00 |
|
github-actions[bot]
|
92af5f5386
|
Post-release preparation for codeql-cli-2.15.4
|
2023-12-06 22:59:22 +00:00 |
|
github-actions[bot]
|
c04457e9e7
|
Release preparation for version 2.15.4
|
2023-12-06 21:11:50 +00:00 |
|
amammad
|
1547cd0546
|
added inline tests, move to experimental dir
|
2023-12-05 18:59:46 +01:00 |
|
amammad
|
2c4d2d3069
|
Merge branch 'main' into amammad-js-CodeInjection_execa
|
2023-12-05 18:38:09 +01:00 |
|
amammad
|
67fb802f29
|
fix conflict
|
2023-12-05 18:37:50 +01:00 |
|
Maiky
|
83cbbd7043
|
Apply docstring changes
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2023-12-05 09:05:29 +01:00 |
|
Jorge
|
8abd1d9855
|
Merge branch 'main' into seclab/dotjs
|
2023-11-30 19:42:18 +01:00 |
|
Felicity Chapman
|
4cb2f53223
|
Remove unwanted period from query name
Our style guide states that names should not end in a period. I'm updating this now to allow us to automate a process for GitHub docs, see: https://github.com/github/codeql/blob/main/docs/query-metadata-style-guide.md#query-name-name
|
2023-11-30 14:31:17 +00:00 |
|
Maiky
|
e6c7fc0ead
|
Fixes CI
|
2023-11-29 19:45:08 +02:00 |
|
Rafael
|
1a05c2e704
|
Added Django test
|
2023-11-29 08:26:49 +01:00 |
|
Rafael
|
0a74a3a765
|
Update javascript/ql/src/change-notes/2023-11-28-django-urls.md
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2023-11-29 08:23:02 +01:00 |
|
Rafael
|
0b0c9e3e48
|
Create 2023-11-28-django-urls.md
|
2023-11-28 22:29:53 +01:00 |
|
Rafael
|
286e3951bf
|
Detect Django template URLs
Django URLs are currently not detected, but flask and nunjucks URL are. (See https://github.com/github/codeql/issues/12267)
|
2023-11-28 22:22:07 +01:00 |
|
Maiky
|
6a3cdc90e2
|
Add change-node
|
2023-11-27 20:58:47 +02:00 |
|
Maiky
|
3bcb411d1a
|
Using Express::RouteSetup
|
2023-11-27 20:31:19 +02:00 |
|
Maiky
|
f623db461a
|
Change qldoc
|
2023-11-27 19:51:13 +02:00 |
|
Maiky
|
bb6ef72e67
|
getArgument returns Cors::Cors
|
2023-11-27 19:36:49 +02:00 |
|
Maiky
|
aa24ce5532
|
Apply suggestions from code review
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2023-11-27 17:48:21 +02:00 |
|
amammad
|
48a9b107b9
|
add query to detect strapi CVe too
|
2023-11-24 10:47:17 +01:00 |
|
Maiky
|
4ef4c92e2c
|
Move Customizations and Query
|
2023-11-23 21:29:09 +01:00 |
|
erik-krogh
|
abb8d65483
|
Merge branch 'main' into amammad-js-SQLI
|
2023-11-23 21:17:58 +01:00 |
|
erik-krogh
|
43c76468c9
|
add change-note
|
2023-11-23 21:17:33 +01:00 |
|