Erik Krogh Kristensen
|
8727060ca7
|
add comment about modes of operation
Co-authored-by: Rasmus Wriedt Larsen <rasmuswriedtlarsen@gmail.com>
|
2021-11-09 11:15:12 +01:00 |
|
Asger Feldthaus
|
87aa39cef2
|
JS: Limited tracking of object literals with methods
|
2021-11-09 11:06:41 +01:00 |
|
Asger F
|
0c6680b2c0
|
Revert "JS: Skip files with unsupported file encoding"
|
2021-11-09 09:07:54 +00:00 |
|
Asger Feldthaus
|
f14f9449ee
|
JS: Use getAMatchedString instead of getConstantString
|
2021-11-08 15:35:35 +01:00 |
|
Asger Feldthaus
|
b3e64f1669
|
JS: Add test
|
2021-11-08 15:32:43 +01:00 |
|
Erik Krogh Kristensen
|
330c2c42b5
|
Merge pull request #7075 from erik-krogh/cwe297
JS: add cwe-297 to `js/disabling-certificate-validation`
|
2021-11-08 14:35:58 +01:00 |
|
Erik Krogh Kristensen
|
a2175a3207
|
add cwe-297 to js/disabling-certificate-validation
|
2021-11-08 13:26:53 +01:00 |
|
Erik Krogh Kristensen
|
507c8addb2
|
add cwe-942 to js/cors-misconfiguration-for-credentials
|
2021-11-08 13:12:19 +01:00 |
|
Erik Krogh Kristensen
|
0ab510f543
|
add test that requires flowToExpr
|
2021-11-08 12:25:45 +01:00 |
|
Erik Krogh Kristensen
|
3d6a5263e0
|
improve qhelp
Co-authored-by: Esben Sparre Andreasen <esbena@github.com>
|
2021-11-08 12:02:39 +01:00 |
|
CodeQL CI
|
6f80387ac1
|
Merge pull request #6993 from asgerf/js/tainted-path-regexp-contains-check
Approved by erik-krogh
|
2021-11-08 01:52:28 -08:00 |
|
Ian Wright
|
95f21b5308
|
Merge pull request #7027 from github/z80coder/faster-callee-api-name-feature
more efficient implementation of calleeApiName
|
2021-11-04 14:23:13 +00:00 |
|
Ian Wright
|
b8d7f52d3e
|
format code
|
2021-11-04 12:28:08 +00:00 |
|
Erik Krogh Kristensen
|
a19627c72f
|
optionally ignore everything after a dash
|
2021-11-04 13:19:44 +01:00 |
|
Erik Krogh Kristensen
|
02f500b9c2
|
Merge branch 'main' into htmlReg
|
2021-11-04 12:58:42 +01:00 |
|
Erik Krogh Kristensen
|
99f5f70345
|
Merge branch 'main' into protoLib
|
2021-11-04 12:53:53 +01:00 |
|
Erik Krogh Kristensen
|
bf5e36e9d4
|
fix docstring
Co-authored-by: Asger F <asgerf@github.com>
|
2021-11-04 12:46:24 +01:00 |
|
Erik Krogh Kristensen
|
4ba5ae09b0
|
add js/sensitive-get-query query
|
2021-11-04 12:30:44 +01:00 |
|
CodeQL CI
|
2895428d5b
|
Merge pull request #6714 from valeria-meli/javascript/ssrf
Approved by asgerf
|
2021-11-04 03:10:27 -07:00 |
|
CodeQL CI
|
5515256e53
|
Merge pull request #7044 from asgerf/js/proto-pollution-fps
Approved by erik-krogh
|
2021-11-04 02:45:46 -07:00 |
|
Erik Krogh Kristensen
|
523c15cd72
|
don't include mode-of-operation into the algorithm names
|
2021-11-03 14:54:50 +01:00 |
|
luciaromeroML
|
e50938588e
|
formatting qll file
|
2021-11-03 10:30:35 -03:00 |
|
Erik Krogh Kristensen
|
3638892d35
|
Merge pull request #6881 from erik-krogh/add-missing-noinline
JS: add pragma[noinline] to predicates where the qldoc mentions join-order
|
2021-11-03 14:21:27 +01:00 |
|
Erik Krogh Kristensen
|
f01ee5914b
|
add a docstring, and rename rawString -> foldedString
|
2021-11-03 14:19:31 +01:00 |
|
Erik Krogh Kristensen
|
7b0ebd3f1a
|
use the context to determine whether or not a node is an operand of a binop
|
2021-11-03 14:09:44 +01:00 |
|
Asger Feldthaus
|
712614a03c
|
JS: Block prototype pollution flow into this
|
2021-11-03 13:33:50 +01:00 |
|
Erik Krogh Kristensen
|
737c747dbb
|
early exit if string becomes too big
|
2021-11-03 13:28:03 +01:00 |
|
Erik Krogh Kristensen
|
1ba6f448cd
|
compute concatenated string and offset at the same time
|
2021-11-03 13:26:19 +01:00 |
|
Erik Krogh Kristensen
|
be46c1f679
|
remove unused import
|
2021-11-03 13:25:09 +01:00 |
|
Asger Feldthaus
|
08bc80ffdb
|
JS: Block prototype pollution assignment flows through .replace()
|
2021-11-03 13:24:29 +01:00 |
|
Asger Feldthaus
|
76e841830f
|
JS: Check for labeled barriers in reachableFromInput
|
2021-11-03 13:10:20 +01:00 |
|
Erik Krogh Kristensen
|
9cf34f19bb
|
Merge branch 'main' into extractBigReg
|
2021-11-03 13:08:51 +01:00 |
|
Erik Krogh Kristensen
|
264f4ab5ab
|
add js/session-fixation query
|
2021-11-03 13:04:41 +01:00 |
|
Erik Krogh Kristensen
|
9d99ce12c4
|
add CWE-497 to js/stack-trace-exposure
|
2021-11-02 15:43:55 +01:00 |
|
Erik Krogh Kristensen
|
2a8807efe4
|
add change note
|
2021-11-02 14:45:33 +01:00 |
|
Erik Krogh Kristensen
|
076a3dca1f
|
add qhelp
|
2021-11-02 14:45:33 +01:00 |
|
Erik Krogh Kristensen
|
d9a214767b
|
add support for node-rsa
|
2021-11-02 14:45:33 +01:00 |
|
Erik Krogh Kristensen
|
49ea53f32b
|
move ExpressJwt that was inside the Hasha module
|
2021-11-02 14:45:33 +01:00 |
|
Erik Krogh Kristensen
|
2c013214f7
|
add Diffie-Hellman from the crypto library
|
2021-11-02 14:45:33 +01:00 |
|
Erik Krogh Kristensen
|
1df8ec2cae
|
add insufficient key size model for node-forge
|
2021-11-02 14:45:33 +01:00 |
|
Erik Krogh Kristensen
|
62039b866c
|
add cryptographic key model to the crypto-js library
|
2021-11-02 14:45:33 +01:00 |
|
Erik Krogh Kristensen
|
028799deb6
|
implement a simple InsufficientKeySize query
|
2021-11-02 14:45:30 +01:00 |
|
Erik Krogh Kristensen
|
7a9315f146
|
use set literal
|
2021-11-02 14:45:14 +01:00 |
|
Asger Feldthaus
|
971f032b5f
|
JS: Autoformat
|
2021-11-02 14:12:05 +01:00 |
|
Asger Feldthaus
|
46bd3e58a3
|
JS: Switch to instanceof base type
|
2021-11-02 14:12:05 +01:00 |
|
Asger Feldthaus
|
5f4c1dd19b
|
JS: Support regexp-based path traversal check
|
2021-11-02 14:12:05 +01:00 |
|
Asger Feldthaus
|
83edcf515b
|
JS: Add test for regexp-based sanitizer
|
2021-11-02 14:12:04 +01:00 |
|
Erik Krogh Kristensen
|
54fba2d6a1
|
Merge pull request #6781 from erik-krogh/ldap
JS: Move LDAP injection out of experimental
|
2021-11-02 13:35:32 +01:00 |
|
Ian Wright
|
6fa9413f8b
|
more efficient implementation of calleeApiName
|
2021-11-02 12:05:33 +00:00 |
|
Erik Krogh Kristensen
|
f7f315adbb
|
Merge pull request #7022 from erik-krogh/cwe319
JS: add cwe-319 to js/clear-text-cookie
|
2021-11-02 12:47:53 +01:00 |
|