Asger Feldthaus
|
66cec65bfb
|
JS: Format HTMLExtractor
|
2021-08-11 12:36:34 +02:00 |
|
Asger Feldthaus
|
8666bc1894
|
JS: Extract placeholders in HTML
|
2021-08-11 12:36:31 +02:00 |
|
Chris Smowton
|
d45d58804b
|
Merge pull request #6466 from github/workflow/coverage/update
Update CSV framework coverage reports
|
2021-08-11 07:56:55 +01:00 |
|
github-actions[bot]
|
5db82651fe
|
Add changed framework coverage reports
|
2021-08-11 00:13:37 +00:00 |
|
jorgectf
|
e6ce10b5c5
|
Merge remote-tracking branch 'origin/main' into jty/python/nosqlInjection
|
2021-08-10 20:01:08 +02:00 |
|
Joe Farebrother
|
7462180dcd
|
Improve handling or array types
|
2021-08-10 16:52:38 +01:00 |
|
Joe Farebrother
|
207c753f6f
|
Update model for getAll
|
2021-08-10 15:05:02 +01:00 |
|
Tamas Vajk
|
2437546009
|
Merge branch 'main' into feature/service-stack
|
2021-08-10 15:16:17 +02:00 |
|
Tamas Vajk
|
243424063a
|
Add pragma inline to getMember/Method/Callable
|
2021-08-10 13:25:56 +02:00 |
|
Tamas Vajk
|
51661bfa62
|
Add pragma noinline to fix uselessUpcast check
|
2021-08-10 13:24:30 +02:00 |
|
Owen Mansel-Chan
|
2000985509
|
Remove duplicate test
|
2021-08-10 11:58:28 +01:00 |
|
Owen Mansel-Chan
|
a55a32f50a
|
Add more missing models
And corresponding tests
|
2021-08-10 11:35:20 +01:00 |
|
Erik Krogh Kristensen
|
01a202fa10
|
fix cfg and dataflow for logical compound assignments
|
2021-08-10 12:17:59 +02:00 |
|
Asger Feldthaus
|
b1ce3d1c5a
|
JS: Do not extract binary HTML
|
2021-08-10 12:15:44 +02:00 |
|
Asger Feldthaus
|
96a2c3f2db
|
JS: Extract .hbs and .ejs as HTML
|
2021-08-10 12:15:44 +02:00 |
|
Asger Feldthaus
|
e678c16d59
|
JS: Parse EJS-style template tags
|
2021-08-10 12:15:44 +02:00 |
|
Asger Feldthaus
|
a7cdf532fa
|
JS: Parse mustache-style tags as expressions
|
2021-08-10 12:15:43 +02:00 |
|
Asger Feldthaus
|
d1c31db06f
|
JS: Reset implicit variable scope when leaving template expr
|
2021-08-10 12:15:43 +02:00 |
|
Benjamin Muskalla
|
8127f63b1e
|
Only include APIs without support
|
2021-08-10 12:05:16 +02:00 |
|
Benjamin Muskalla
|
26d4269071
|
Use FlowSources for coverage tracking
|
2021-08-10 12:02:56 +02:00 |
|
Benjamin Muskalla
|
c48586ff80
|
Implement coverage tracking using dataflow nodes
|
2021-08-10 11:38:01 +02:00 |
|
Benjamin Muskalla
|
5b55a83aaa
|
Use basename for jars
|
2021-08-10 11:37:19 +02:00 |
|
Tom Hvitved
|
d658ef1dcd
|
Merge pull request #6449 from hvitved/python/contains-in-scope-perf
Python: Avoid bad join in `AstExtended::AstNode::containsInScope`
|
2021-08-10 10:27:00 +02:00 |
|
Chris Smowton
|
cb73100717
|
Merge pull request #6458 from github/workflow/coverage/update
Update CSV framework coverage reports
|
2021-08-10 09:23:53 +01:00 |
|
Chris Smowton
|
9f9c76390f
|
Nudge CI
|
2021-08-10 09:12:18 +01:00 |
|
Asger Feldthaus
|
d83f5a9cd7
|
JS: Update StringConcatenation tests after handling 0-arg join calls
|
2021-08-10 08:56:36 +02:00 |
|
Asger Feldthaus
|
a3e56dea5e
|
JS: Factor out StringOps::substringMethodName
|
2021-08-10 08:55:04 +02:00 |
|
Asger Feldthaus
|
1074d409fb
|
JS: Autoformat
|
2021-08-10 08:55:03 +02:00 |
|
Asger Feldthaus
|
6ef83f8015
|
JS: Change note
|
2021-08-10 08:55:03 +02:00 |
|
Asger Feldthaus
|
f1bcfa287b
|
JS: Add more tests
|
2021-08-10 08:55:03 +02:00 |
|
Asger Feldthaus
|
4efea4316e
|
JS: Use TaintedUrlSuffix flow label in jQuery xss
|
2021-08-10 08:55:03 +02:00 |
|
Asger F
|
077aa05336
|
Merge pull request #6448 from asgerf/js/handlebars-extraction-preliminary
JS: Update locations in Angular2 test
|
2021-08-10 08:50:18 +02:00 |
|
github-actions[bot]
|
22fe354aab
|
Add changed framework coverage reports
|
2021-08-10 00:07:47 +00:00 |
|
Owen Mansel-Chan
|
54fdfe3906
|
Make helper functions more consistent
|
2021-08-09 17:18:03 +01:00 |
|
Owen Mansel-Chan
|
2d31bb8d64
|
Remove toString taint propagation
We do not do this for other overrides of toString
|
2021-08-09 17:18:02 +01:00 |
|
Owen Mansel-Chan
|
487a46ae77
|
Improve treatment of new and old package name
|
2021-08-09 16:25:11 +01:00 |
|
Chris Smowton
|
021e405294
|
Elaborate change note a little
|
2021-08-09 15:33:21 +01:00 |
|
Chris Smowton
|
5ba9347281
|
Merge pull request #6006 from artem-smotrakov/timing-attacks
Java: Timing attacks while comparing results of cryptographic operations
|
2021-08-09 15:30:47 +01:00 |
|
Chris Smowton
|
171dc26531
|
Fix test reference and expectations
|
2021-08-09 13:56:55 +01:00 |
|
Tom Hvitved
|
ea6d51f123
|
Python: Avoid bad join in AstExtended::AstNode::containsInScope
|
2021-08-09 11:20:57 +02:00 |
|
Asger Feldthaus
|
88500a3fa3
|
JS: Update TRAP test output
|
2021-08-09 11:19:08 +02:00 |
|
Asger Feldthaus
|
2836d465e4
|
JS: Update locations in Angular2 test
|
2021-08-09 11:03:15 +02:00 |
|
Tamas Vajk
|
91bd3d1a11
|
Cache getName to improve performance
|
2021-08-09 10:28:31 +02:00 |
|
Tom Hvitved
|
15db6dfb10
|
Merge pull request #6431 from hvitved/csharp/silence-xml-extraction
C#: Silence XML extraction commands
|
2021-08-09 09:36:23 +02:00 |
|
CodeQL CI
|
562ba49f4e
|
Merge pull request #6406 from erik-krogh/cleanCfg
Approved by asgerf
|
2021-08-09 00:21:31 -07:00 |
|
Tamás Vajk
|
c1cf2a1c5f
|
Merge pull request #5579 from edvraa/cookies
C#: HttpOnly and Secure cookie queries
|
2021-08-09 08:58:11 +02:00 |
|
Owen Mansel-Chan
|
1997dfbb4a
|
Remove unnecessary casts
|
2021-08-08 14:03:57 +01:00 |
|
Owen Mansel-Chan
|
f94e467076
|
Fixes to models and tests
Running the test generator script again showed many missing tests.
|
2021-08-08 14:03:48 +01:00 |
|
Owen Mansel-Chan
|
377403d525
|
Remove redundant models and corresponding test
Iterator.next is already modelled
|
2021-08-08 13:57:51 +01:00 |
|
Owen Mansel-Chan
|
5d3f10824e
|
Fix erroneous treatment of varargs in models
|
2021-08-08 13:57:50 +01:00 |
|