CodeQL CI
|
8129d0c0ac
|
Merge pull request #4762 from asgerf/js/template-sinks-in-code-injection
Approved by erik-krogh, mchammer01
|
2020-12-07 04:35:11 -08:00 |
|
Sauyon Lee
|
17e450f227
|
JavaScript: Factor out HTML extractor
|
2020-12-06 05:04:10 -08:00 |
|
CodeQL CI
|
0f5f0ed99e
|
Merge pull request #4776 from asgerf/js/electron-openshell
Approved by erik-krogh
|
2020-12-04 09:12:44 +00:00 |
|
Asger Feldthaus
|
f0516dd9e0
|
JS: Address review comments
|
2020-12-04 09:07:44 +00:00 |
|
Asger Feldthaus
|
20d9848f07
|
JS: Add test case
|
2020-12-03 15:08:43 +00:00 |
|
Asger Feldthaus
|
68d2bc861d
|
JS: Update test expectations
|
2020-12-03 15:01:50 +00:00 |
|
Asger Feldthaus
|
e66a49bea6
|
JS: Change note
|
2020-12-03 13:58:40 +00:00 |
|
Asger Feldthaus
|
ec6b8d6d3a
|
JS: Remove old workaround for template literals in import
|
2020-12-03 13:58:40 +00:00 |
|
Asger Feldthaus
|
757398f5fd
|
JS: Add upgrade script and stats
|
2020-12-03 13:58:39 +00:00 |
|
Asger Feldthaus
|
3b3052d792
|
JS: Autoformat
|
2020-12-03 13:58:39 +00:00 |
|
Asger Feldthaus
|
5676891e44
|
JS: Add TemplateLiteralTypeExpr
|
2020-12-03 13:58:39 +00:00 |
|
Asger Feldthaus
|
9da5c5cc70
|
JS: Update to TypeScript 4.1.2
|
2020-12-03 13:58:39 +00:00 |
|
Asger F
|
254072dd6d
|
Merge pull request #4546 from toufik-airane/main
JS: Add ElectronShellOpenExternalSink class for Electron framework security
|
2020-12-03 13:20:46 +00:00 |
|
CodeQL CI
|
edbbc846d0
|
Merge pull request #4753 from max-schaefer/js/more-nosql-query-args
Approved by asgerf, mchammer01
|
2020-12-03 08:46:47 +00:00 |
|
Asger Feldthaus
|
412939d071
|
JS: Autoformat
|
2020-12-02 13:08:32 +00:00 |
|
Asger Feldthaus
|
5561e8f1f6
|
JS: Delete old query and update qhelp
|
2020-12-01 17:05:48 +00:00 |
|
Asger Feldthaus
|
6211fe718b
|
JS: Add test
|
2020-12-01 17:05:48 +00:00 |
|
Asger Feldthaus
|
1459d9197d
|
JS: Adjust alert message for template sinks
|
2020-12-01 17:05:48 +00:00 |
|
Asger Feldthaus
|
8412a6bcbb
|
JS: Add template injection sinks to js/code-injection
|
2020-12-01 17:05:48 +00:00 |
|
Max Schaefer
|
978d2db252
|
JavaScript: Add models for more Mongoose methods.
|
2020-11-30 16:32:13 +00:00 |
|
Anders Schack-Mulligen
|
8f2094f0bf
|
Autoformat.
|
2020-11-30 14:42:38 +01:00 |
|
Jonas Jensen
|
ad4b2beafa
|
Merge pull request #4727 from criemen/remove-abstract-classes
C++/C#/JS/Python/Java XML.qll: Remove abstract from class hierarchy.
|
2020-11-27 08:17:21 +01:00 |
|
Cornelius Riemenschneider
|
3bfb398516
|
Autoformat XML.qll.
|
2020-11-25 18:20:50 +01:00 |
|
Cornelius Riemenschneider
|
7eec988fb5
|
XML.qll: Remove abstract from class hierarchy.
|
2020-11-25 17:22:03 +01:00 |
|
CodeQL CI
|
34ffcb5677
|
Merge pull request #4593 from asgerf/js/react-hot
Approved by erik-krogh
|
2020-11-25 12:01:38 +00:00 |
|
CodeQL CI
|
395403789e
|
Merge pull request #4585 from erik-krogh/moreReDoS
Approved by asgerf
|
2020-11-24 18:52:36 +00:00 |
|
CodeQL CI
|
4be158b362
|
Merge pull request #4708 from erik-krogh/emptyName
Approved by asgerf
|
2020-11-24 17:34:55 +00:00 |
|
CodeQL CI
|
8c68463e76
|
Merge pull request #4711 from erik-krogh/locType
Approved by asgerf
|
2020-11-24 13:10:32 +00:00 |
|
Erik Krogh Kristensen
|
f03429a4b8
|
change description for source root folder
|
2020-11-23 23:46:44 +01:00 |
|
Erik Krogh Kristensen
|
33dab1717e
|
treat nodes with type "Location" as a location source - but not if we can track it from an original node with type "Location"
|
2020-11-23 17:03:50 +01:00 |
|
Erik Krogh Kristensen
|
f7f9beeefd
|
avoid reporting empty names in js/exposure-of-private-files
|
2020-11-23 14:24:42 +01:00 |
|
Erik Krogh Kristensen
|
02d5fbf46b
|
remove superfluous space
|
2020-11-23 14:22:16 +01:00 |
|
Erik Krogh Kristensen
|
234730419b
|
restrict computation of ConcatenationRoot::getConstantStringParts to results that are less than 1 million chars long
|
2020-11-23 10:29:47 +01:00 |
|
Asger Feldthaus
|
f894cf2074
|
JS: Add support for react-hot-loader
|
2020-11-20 15:28:32 +00:00 |
|
Asger Feldthaus
|
16429c8ca4
|
JS: followed -> followed by
|
2020-11-20 14:44:25 +00:00 |
|
Asger Feldthaus
|
7536c49c6f
|
JS: Use getAParameter and not getReceiver instead of getASuccessor
|
2020-11-20 10:34:30 +00:00 |
|
Asger F
|
405f07720a
|
Apply suggestions from code review
Co-authored-by: Max Schaefer <54907921+max-schaefer@users.noreply.github.com>
|
2020-11-20 10:21:19 +00:00 |
|
Asger Feldthaus
|
b34df9ff33
|
JS: Autoformat
|
2020-11-20 10:15:35 +00:00 |
|
Asger Feldthaus
|
f737f34dcd
|
JS: Add UntrustedDataToExternalApi query
|
2020-11-19 13:42:25 +00:00 |
|
Erik Krogh Kristensen
|
a3b21ad43b
|
Apply suggestions from code review
Co-authored-by: Asger F <asgerf@github.com>
|
2020-11-19 11:42:12 +01:00 |
|
Erik Krogh Kristensen
|
cc1d797cef
|
adjust top comment to reflect what the query does, and add comment about which kind of accepting state is assumed.
|
2020-11-18 21:32:31 +01:00 |
|
Erik Krogh Kristensen
|
58c31f0eca
|
prune more regexps initially in the ReDoS query
|
2020-11-18 15:14:46 +01:00 |
|
Erik Krogh Kristensen
|
c4153a617e
|
remove duplicated test cases from ReDoS, and adjust variables names to match test output
|
2020-11-18 14:49:09 +01:00 |
|
Erik Krogh Kristensen
|
8270bf5bb9
|
make the character search skip unencodable characters
|
2020-11-18 11:55:49 +01:00 |
|
Erik Krogh Kristensen
|
55f2f86a26
|
limit the search of state-pairs to the ones that are reachable within the given length
|
2020-11-18 09:23:35 +01:00 |
|
Erik Krogh Kristensen
|
c4d7533701
|
Merge branch 'main' into moreReDoS
|
2020-11-17 17:34:49 +01:00 |
|
Erik Krogh Kristensen
|
97acf1fd87
|
fix FP related to inverted character classes choosing a char that was not matched by the char class
|
2020-11-17 17:34:43 +01:00 |
|
CodeQL CI
|
09cfb24afa
|
Merge pull request #4648 from erik-krogh/regexpParse
Approved by asgerf
|
2020-11-16 08:20:40 +00:00 |
|
Erik Krogh Kristensen
|
a49b99b18c
|
autoformat
|
2020-11-13 20:06:17 +01:00 |
|
Erik Krogh Kristensen
|
affb11b0e3
|
changes based on review
|
2020-11-13 19:46:37 +01:00 |
|