Napalys Klicius
|
d1e769ba54
|
Merge pull request #19422 from Napalys/js/shelljs
JS: Modeling of `ShellJS` functions
|
2025-05-02 14:18:44 +02:00 |
|
Napalys Klicius
|
871e93d9fe
|
Update javascript/ql/lib/semmle/javascript/frameworks/ShellJS.qll
Co-authored-by: Asger F <asgerf@github.com>
|
2025-05-02 13:39:46 +02:00 |
|
Tamás Vajk
|
cb1c3736fe
|
Merge pull request #19413 from tamasvajk/quality/query-suite-selector
Add code quality suite selector and use that in the code quality suites
|
2025-05-02 08:18:48 +02:00 |
|
Owen Mansel-Chan
|
e0549483fd
|
Merge pull request #19429 from owen-mc/fix-cwe-tags-missing-leading-zero
Fix cwe tags to include leading zero
|
2025-05-01 14:09:54 +01:00 |
|
Owen Mansel-Chan
|
0863c87572
|
Add change notes
|
2025-05-01 10:33:24 +01:00 |
|
Napalys Klicius
|
68a9dd9f9e
|
Address comments
|
2025-05-01 11:19:41 +02:00 |
|
Napalys Klicius
|
d4b5ef6a66
|
Refactor process.env handling in CleartextLogging and IndirectCommandInjection modules to use ThreatModelSource
|
2025-05-01 11:14:15 +02:00 |
|
Napalys Klicius
|
33d8ffa83e
|
Added test cases for shelljs.env
|
2025-05-01 11:11:29 +02:00 |
|
Napalys Klicius
|
602500e280
|
Added change note
|
2025-05-01 11:09:56 +02:00 |
|
Napalys Klicius
|
40d176a770
|
Added model for shelljs.env
|
2025-05-01 11:09:47 +02:00 |
|
Owen Mansel-Chan
|
cf614a596d
|
Fix cwe tags to include leading zero
|
2025-04-30 16:43:03 +01:00 |
|
Napalys Klicius
|
9624a413e4
|
Added change note
|
2025-04-30 14:57:00 +02:00 |
|
Napalys Klicius
|
71f1b82a56
|
Added support for fastify.all
|
2025-04-30 14:54:09 +02:00 |
|
Napalys Klicius
|
6d61766366
|
Added test case for fastify.all
|
2025-04-30 14:50:35 +02:00 |
|
Asger F
|
8ebbfb198e
|
Merge pull request #19412 from asgerf/js/promise-all
JS: Better type-tracking through Promise.all()
|
2025-04-30 14:19:12 +02:00 |
|
Napalys Klicius
|
18cea2d6a5
|
Added support for shelljs.cmd and async-shelljs.asyncExec
|
2025-04-30 13:37:02 +02:00 |
|
Napalys Klicius
|
25d04f1cdd
|
Added support for shelljs.which
|
2025-04-30 13:35:17 +02:00 |
|
Napalys Klicius
|
f6fae7ad60
|
Added test cases for cmd, which and asyncExec
|
2025-04-30 13:33:31 +02:00 |
|
Asger F
|
da5d799152
|
JS: Change note
|
2025-04-30 11:59:47 +02:00 |
|
Napalys Klicius
|
6de38b1827
|
Merge pull request #19300 from Napalys/js/fastify
JS: Added support for `fastify.addHook`
|
2025-04-29 18:32:25 +02:00 |
|
Tamas Vajk
|
d56c5225f6
|
Use code-quality-selectors in JS suite
|
2025-04-29 16:23:08 +02:00 |
|
Asger F
|
eae1e1cb02
|
JS: Make API graphs rely on type-tracking steps in general
|
2025-04-29 15:08:19 +02:00 |
|
Asger F
|
e40b93b8a3
|
JS: Add type-tracking step through simple Promise.all() calls
|
2025-04-29 15:08:18 +02:00 |
|
Asger F
|
6e64a22579
|
Merge pull request #19393 from asgerf/js/json-extractor-trailing-commas2
JS: Tolerate trailing commas in JSON objects
|
2025-04-29 09:40:38 +02:00 |
|
Nick Rolfe
|
50f7ee1158
|
Merge pull request #19401 from github/post-release-prep/codeql-cli-2.21.2
Post-release preparation for codeql-cli-2.21.2
|
2025-04-28 16:16:21 +01:00 |
|
github-actions[bot]
|
2e0699ab2b
|
Post-release preparation for codeql-cli-2.21.2
|
2025-04-28 14:03:28 +00:00 |
|
Napalys Klicius
|
8b53f8f2a6
|
Fix, prevent addHook return values from being treated as XSS sinks
|
2025-04-28 14:22:51 +02:00 |
|
Napalys Klicius
|
73309fb9dd
|
Updated modeling of aws-sdk with MaD
|
2025-04-28 14:00:12 +02:00 |
|
Napalys Klicius
|
654177daa7
|
Fixed naming acronyms to be PascalCase
|
2025-04-28 14:00:12 +02:00 |
|
Napalys Klicius
|
f7f9fb823a
|
Updated takesConfigurationObject with API graphs
|
2025-04-28 14:00:12 +02:00 |
|
Napalys Klicius
|
42d5b80e81
|
Added support for AWS.Credentials hardcoded credentials
|
2025-04-28 14:00:12 +02:00 |
|
Napalys Klicius
|
f69037c176
|
Added ability to detect direct write to global AWS.config
|
2025-04-28 14:00:12 +02:00 |
|
Napalys Klicius
|
05e4677fd1
|
Added ability to detect new AWS.ServiceName cases with hardcoded credentials
|
2025-04-28 14:00:12 +02:00 |
|
Napalys Klicius
|
e6450a17ec
|
Added test cases for individual AWS services, direct modification of global credentials and AWS.Credentials
|
2025-04-28 14:00:12 +02:00 |
|
github-actions[bot]
|
625354c46e
|
Release preparation for version 2.21.2
|
2025-04-28 10:55:22 +00:00 |
|
Asger F
|
152d6f3c29
|
JS: Tolerate trailing comma in JSON objects
|
2025-04-28 10:56:48 +02:00 |
|
Asger F
|
6dd8114f00
|
JS: Add test with trailing comma in JSON object
|
2025-04-28 10:56:34 +02:00 |
|
Tamas Vajk
|
a4a24470c8
|
Add query suite inclusion tests for actions, csharp, go, javascript, ruby, rust
|
2025-04-25 14:06:17 +02:00 |
|
Michael Nebel
|
2e0ce44fde
|
Javascript: Update test files.
|
2025-04-23 15:41:41 +02:00 |
|
Napalys
|
fdfdcc0d93
|
Undo unnecessary name tracking for request, response objects
|
2025-04-22 14:16:45 +02:00 |
|
Asger F
|
00661b62dc
|
JS: Add isMiddlewareSetup() hook to Routing model
|
2025-04-22 12:00:02 +02:00 |
|
Asger F
|
c2cab184ac
|
Merge pull request #19283 from asgerf/js/rest-pattern-fix
JS: Fix missing flow into rest pattern lvalue
|
2025-04-22 10:37:36 +02:00 |
|
github-actions[bot]
|
d78736b1bf
|
Post-release preparation for codeql-cli-2.21.1
|
2025-04-15 16:33:15 +00:00 |
|
Napalys
|
5c3556da66
|
Add user-controlled property tracking and update code injection alerts in Fastify hooks
|
2025-04-15 09:41:52 +02:00 |
|
Napalys
|
9b194ea613
|
Added addHook to RouteSetup thus now it is recognized now as rouute handler
|
2025-04-15 09:37:13 +02:00 |
|
Napalys
|
c175081698
|
Added test cases for fastify.addHook
|
2025-04-15 09:33:41 +02:00 |
|
Napalys
|
f1a3293f4c
|
Added change note
|
2025-04-15 09:27:51 +02:00 |
|
github-actions[bot]
|
b961c5961d
|
Release preparation for version 2.21.1
|
2025-04-14 09:53:06 +00:00 |
|
Napalys Klicius
|
86313715a4
|
Merge pull request #19184 from Napalys/js/request_handlers
JS: Support for `Request` and `NextRequest`
|
2025-04-14 08:07:24 +02:00 |
|
Asger F
|
6c01709048
|
JS: Update more test output
|
2025-04-11 15:15:22 +02:00 |
|