semmle-qlci
|
98034aaa53
|
Merge pull request #2988 from asger-semmle/js/autoformat-again-again
Approved by esbena
|
2020-03-04 21:20:52 +00:00 |
|
Asger Feldthaus
|
53569453ba
|
JS: Autoformat again
|
2020-03-04 19:28:24 +00:00 |
|
semmle-qlci
|
c5d39039bc
|
Merge pull request #2962 from erik-krogh/YetAnotherSanitizer
Approved by asgerf
|
2020-03-04 15:27:09 +00:00 |
|
Esben Sparre Andreasen
|
4625217a68
|
Merge branch 'master' of github.com:Semmle/ql into js/more-fs-modules
|
2020-03-03 15:07:51 +01:00 |
|
Erik Krogh Kristensen
|
f03c67266a
|
add taint step for replace call that only removes dots
|
2020-03-03 12:58:06 +01:00 |
|
Erik Krogh Kristensen
|
95819c8731
|
use RegExpTerm to generalize predicate
|
2020-03-03 12:34:18 +01:00 |
|
Erik Krogh Kristensen
|
622a2fcfdc
|
use regexp term instead of char class
|
2020-03-03 12:24:13 +01:00 |
|
semmle-qlci
|
57b3e6addf
|
Merge pull request #2958 from erik-krogh/InnerPrefix
Approved by asgerf
|
2020-03-03 11:10:44 +00:00 |
|
Erik Krogh Kristensen
|
bc13204193
|
refactor header checks to be based on dominance
|
2020-03-03 12:04:31 +01:00 |
|
semmle-qlci
|
7f3f629d39
|
Merge pull request #2913 from asger-semmle/js/prototype-pollution-path
Approved by erik-krogh
|
2020-03-03 10:29:47 +00:00 |
|
semmle-qlci
|
b3cbf8baa8
|
Merge pull request #2960 from erik-krogh/OverloadsWithThis
Approved by asgerf
|
2020-03-03 10:10:00 +00:00 |
|
Esben Sparre Andreasen
|
adddebf039
|
Merge branch 'master' of github.com:Semmle/ql into js/more-fs-modules
|
2020-03-03 10:55:16 +01:00 |
|
semmle-qlci
|
e1c5449885
|
Merge pull request #2867 from erik-krogh/UselessCat
Approved by esbena
|
2020-03-03 09:10:25 +00:00 |
|
Erik Krogh Kristensen
|
9016f43d80
|
update expected output
|
2020-03-03 10:04:57 +01:00 |
|
Erik Krogh Kristensen
|
53d1cd33f6
|
support sanitizers that remove all forward slashes
|
2020-03-02 21:34:40 +01:00 |
|
Erik Krogh Kristensen
|
68fb8c52e9
|
check the type of the this-type, instead of the AST-node
|
2020-03-02 16:35:16 +01:00 |
|
Erik Krogh Kristensen
|
e0fcc4af6a
|
handle this parameters when finding unreachable overloads
|
2020-03-02 16:26:00 +01:00 |
|
Erik Krogh Kristensen
|
26fd17bf39
|
recognize utility functions implementing a StartsWith check
|
2020-03-02 13:00:58 +01:00 |
|
Asger Feldthaus
|
e405a9769c
|
JS: Really autoformat everything
|
2020-03-02 10:48:33 +00:00 |
|
Erik Krogh Kristensen
|
c14a485ca7
|
recognize more HttpResponseSink by restricting the hasNonHtmlHeader check
|
2020-03-02 10:10:34 +01:00 |
|
Erik Krogh Kristensen
|
71ff32e930
|
recognize another prefix check for js/path-injection
|
2020-02-28 14:55:41 +01:00 |
|
Esben Sparre Andreasen
|
a589061bee
|
JS: add type-tracking to the fs-module and model the original-fs
|
2020-02-28 12:54:59 +01:00 |
|
Esben Sparre Andreasen
|
5a3a1c480d
|
JS: add tests for the fs-module and friends
|
2020-02-28 12:21:10 +01:00 |
|
Erik Krogh Kristensen
|
ce9cd53bf1
|
Merge remote-tracking branch 'upstream/master' into UselessCat
|
2020-02-28 09:56:23 +01:00 |
|
Asger Feldthaus
|
52ebe49a0b
|
JS: Flag deep assignments in prototype pollution query
|
2020-02-27 12:17:55 +00:00 |
|
Erik Krogh Kristensen
|
9c06c48dc7
|
Merge pull request #2884 from esbena/js/practically-exploitable-redos
JS: add query js/exploitable-polynomial-redos
|
2020-02-27 10:19:17 +01:00 |
|
Esben Sparre Andreasen
|
1b73cee692
|
JS: add js/exploitable-polynomial-redos
|
2020-02-27 08:42:43 +01:00 |
|
Erik Krogh Kristensen
|
dc6bfad023
|
Merge remote-tracking branch 'upstream/master' into CVE481
|
2020-02-25 16:25:03 +01:00 |
|
semmle-qlci
|
03b882381a
|
Merge pull request #2723 from esbena/js/support-path-is-inside
Approved by asgerf
|
2020-02-25 11:21:24 +00:00 |
|
Erik Krogh Kristensen
|
87d283aa6c
|
add tests for third party command execution libraries (and two small fixes)
|
2020-02-25 10:50:59 +01:00 |
|
Asger F
|
160fc48803
|
Merge pull request #2896 from asger-semmle/typescript-3.8
TS: Support Typescript 3.8
|
2020-02-25 08:19:01 +00:00 |
|
Esben Sparre Andreasen
|
5baba62154
|
JS: model path-is-inside+is-path-inside for js/path-injection
|
2020-02-24 23:10:15 +01:00 |
|
Esben Sparre Andreasen
|
86b836cd29
|
JS: add tests for js/path-injection
|
2020-02-24 23:03:42 +01:00 |
|
semmle-qlci
|
317356e591
|
Merge pull request #2898 from asger-semmle/js/prototype-pollution-isobject-sanitizers
Approved by erik-krogh
|
2020-02-24 13:35:32 +00:00 |
|
Erik Krogh Kristensen
|
fb94af9764
|
remove the last dependency on PrettyPrinting
|
2020-02-24 13:18:15 +01:00 |
|
Erik Krogh Kristensen
|
473787a426
|
refactor the getOptionsArg predicate into the SystemCommandExecution class
|
2020-02-24 12:59:20 +01:00 |
|
Asger Feldthaus
|
260b243c28
|
TS: Add test case to DeclBeforeUse
|
2020-02-24 11:40:27 +00:00 |
|
Asger Feldthaus
|
f923b24bc5
|
JS: Fix test
|
2020-02-24 11:19:23 +00:00 |
|
Erik Krogh Kristensen
|
44db0f4e5d
|
better printing of the options arg
|
2020-02-21 15:39:49 +01:00 |
|
Asger Feldthaus
|
d1df251b92
|
JS: Proto pollution: Add is-plain-object sanitizer
|
2020-02-21 14:38:33 +00:00 |
|
Erik Krogh Kristensen
|
90e5671d98
|
Merge branch 'master' of git.semmle.com:Semmle/ql into CVE481
|
2020-02-21 15:25:07 +01:00 |
|
Erik Krogh Kristensen
|
75410e5760
|
big refactor of UselessUseOfCal
|
2020-02-21 14:26:42 +01:00 |
|
Erik Krogh Kristensen
|
b1cbfce50b
|
use SystemCommandExecution and a few small fixes
|
2020-02-20 14:17:37 +01:00 |
|
Erik Krogh Kristensen
|
03e295ef11
|
Merge branch 'master' of git.semmle.com:Semmle/ql into CVE74
|
2020-02-20 12:19:32 +01:00 |
|
semmle-qlci
|
f6af5da7f7
|
Merge pull request #2778 from erik-krogh/FalsySanitizer
Approved by asgerf
|
2020-02-20 11:17:03 +00:00 |
|
Erik Krogh Kristensen
|
63036aa444
|
Merge branch 'master' of git.semmle.com:Semmle/ql into CVE74
|
2020-02-20 12:09:06 +01:00 |
|
Erik Krogh Kristensen
|
12c0291dde
|
require that an options object has a known set of properties
|
2020-02-20 11:35:11 +01:00 |
|
Erik Krogh Kristensen
|
b5ef45e6c2
|
add isSync predicate to SystemCommandExecution
|
2020-02-20 11:30:23 +01:00 |
|
Erik Krogh Kristensen
|
a193cb110e
|
support arrow functions in the callbacks
|
2020-02-20 11:13:39 +01:00 |
|
Erik Krogh Kristensen
|
56f3e431f9
|
update expected output
|
2020-02-20 10:28:53 +01:00 |
|