Erik Krogh Kristensen
|
ce9cd53bf1
|
Merge remote-tracking branch 'upstream/master' into UselessCat
|
2020-02-28 09:56:23 +01:00 |
|
Erik Krogh Kristensen
|
d8a96dd771
|
change name to suggestion from previous code review
|
2020-02-28 09:55:15 +01:00 |
|
Erik Krogh Kristensen
|
922779e049
|
remove double a/an and adjust line lenghts
|
2020-02-28 09:48:07 +01:00 |
|
Erik Krogh Kristensen
|
17f1974e05
|
Apply suggestions from code review
Co-Authored-By: mc <42146119+mchammer01@users.noreply.github.com>
|
2020-02-28 09:43:32 +01:00 |
|
semmle-qlci
|
ec90627a64
|
Merge pull request #2909 from yo-h/experimental
Approved by aschackmull, jbj, max-schaefer, tausbn
|
2020-02-28 03:15:58 +00:00 |
|
Asger Feldthaus
|
52ebe49a0b
|
JS: Flag deep assignments in prototype pollution query
|
2020-02-27 12:17:55 +00:00 |
|
Erik Krogh Kristensen
|
a872d7c5c5
|
add comment about negative optionsArg
|
2020-02-27 12:42:22 +01:00 |
|
Erik Krogh Kristensen
|
bb911bbbf1
|
Apply suggestions from code review
Co-Authored-By: Esben Sparre Andreasen <esbena@github.com>
|
2020-02-27 12:38:06 +01:00 |
|
Asger Feldthaus
|
fefcf1a7a6
|
JS: Autoformat everything
|
2020-02-27 09:41:01 +00:00 |
|
Erik Krogh Kristensen
|
9c06c48dc7
|
Merge pull request #2884 from esbena/js/practically-exploitable-redos
JS: add query js/exploitable-polynomial-redos
|
2020-02-27 10:19:17 +01:00 |
|
Esben Sparre Andreasen
|
1b73cee692
|
JS: add js/exploitable-polynomial-redos
|
2020-02-27 08:42:43 +01:00 |
|
Erik Krogh Kristensen
|
dc6bfad023
|
Merge remote-tracking branch 'upstream/master' into CVE481
|
2020-02-25 16:25:03 +01:00 |
|
semmle-qlci
|
03b882381a
|
Merge pull request #2723 from esbena/js/support-path-is-inside
Approved by asgerf
|
2020-02-25 11:21:24 +00:00 |
|
Erik Krogh Kristensen
|
c83c27cbc4
|
add extra sanity-check that the output looks good
|
2020-02-25 11:11:58 +01:00 |
|
Erik Krogh Kristensen
|
8d26f32199
|
arg -> param
|
2020-02-25 10:53:07 +01:00 |
|
Erik Krogh Kristensen
|
87d283aa6c
|
add tests for third party command execution libraries (and two small fixes)
|
2020-02-25 10:50:59 +01:00 |
|
Erik Krogh Kristensen
|
d540caecdd
|
Apply suggestions from code review
Co-Authored-By: Esben Sparre Andreasen <esbena@github.com>
|
2020-02-25 10:04:51 +01:00 |
|
Asger F
|
160fc48803
|
Merge pull request #2896 from asger-semmle/typescript-3.8
TS: Support Typescript 3.8
|
2020-02-25 08:19:01 +00:00 |
|
Esben Sparre Andreasen
|
5baba62154
|
JS: model path-is-inside+is-path-inside for js/path-injection
|
2020-02-24 23:10:15 +01:00 |
|
Esben Sparre Andreasen
|
86b836cd29
|
JS: add tests for js/path-injection
|
2020-02-24 23:03:42 +01:00 |
|
semmle-qlci
|
aadb148c1c
|
Merge pull request #2855 from asger-semmle/js/returned-partial-call
Approved by esbena
|
2020-02-24 21:37:41 +00:00 |
|
yo-h
|
43bcd5b26c
|
Add guidelines for experimental CodeQL queries and libraries
|
2020-02-24 15:08:31 -05:00 |
|
Erik Krogh Kristensen
|
afd6ea2628
|
small correction in doc + autoformat
|
2020-02-24 17:54:29 +01:00 |
|
Erik Krogh Kristensen
|
b20e8520f6
|
add default message if not pretty printed call can be created
|
2020-02-24 14:52:08 +01:00 |
|
semmle-qlci
|
317356e591
|
Merge pull request #2898 from asger-semmle/js/prototype-pollution-isobject-sanitizers
Approved by erik-krogh
|
2020-02-24 13:35:32 +00:00 |
|
Erik Krogh Kristensen
|
a779ae58a8
|
add qhelp
|
2020-02-24 14:03:41 +01:00 |
|
Erik Krogh Kristensen
|
fb94af9764
|
remove the last dependency on PrettyPrinting
|
2020-02-24 13:18:15 +01:00 |
|
Erik Krogh Kristensen
|
051de247b0
|
change regexpMatch to regexpFind
|
2020-02-24 13:11:30 +01:00 |
|
Erik Krogh Kristensen
|
a768e937f0
|
complete qldoc
|
2020-02-24 13:08:50 +01:00 |
|
Erik Krogh Kristensen
|
473787a426
|
refactor the getOptionsArg predicate into the SystemCommandExecution class
|
2020-02-24 12:59:20 +01:00 |
|
Asger Feldthaus
|
01309d7c2e
|
TS: Add test for named re-export and exportsAs
|
2020-02-24 11:40:28 +00:00 |
|
Asger Feldthaus
|
78954489fb
|
TS: Fix expected output
|
2020-02-24 11:40:28 +00:00 |
|
Asger Feldthaus
|
4e1bd9056c
|
TS: Fix javadoc
|
2020-02-24 11:40:28 +00:00 |
|
Asger Feldthaus
|
18974bad1c
|
TS: Add upgrade script and stats
|
2020-02-24 11:40:27 +00:00 |
|
Asger Feldthaus
|
47673c6e21
|
TS: Disable export analysis for type-only exports
|
2020-02-24 11:40:27 +00:00 |
|
Asger Feldthaus
|
16c909b433
|
TS: Add test case for import type * as ns
|
2020-02-24 11:40:27 +00:00 |
|
Asger Feldthaus
|
260b243c28
|
TS: Add test case to DeclBeforeUse
|
2020-02-24 11:40:27 +00:00 |
|
Asger Feldthaus
|
8d58aad0f2
|
TS: Support type-only import/export
|
2020-02-24 11:40:27 +00:00 |
|
Asger Feldthaus
|
0351f0b775
|
TS: Add test and documentation for private fields
|
2020-02-24 11:40:27 +00:00 |
|
Asger Feldthaus
|
8531c113a1
|
TS: Fix imports
|
2020-02-24 11:40:27 +00:00 |
|
Asger Feldthaus
|
9b52acc62a
|
TS: Handle export * as ns
|
2020-02-24 11:40:27 +00:00 |
|
Asger Feldthaus
|
7f939fe1e4
|
TS: Update to TypeScript 3.8.2
|
2020-02-24 11:40:27 +00:00 |
|
semmle-qlci
|
94aa77748d
|
Merge pull request #2810 from erik-krogh/CVE74
Approved by asgerf
|
2020-02-24 11:32:42 +00:00 |
|
Asger Feldthaus
|
f923b24bc5
|
JS: Fix test
|
2020-02-24 11:19:23 +00:00 |
|
Erik Krogh Kristensen
|
75c1852ee4
|
doc changes from review
Co-Authored-By: Esben Sparre Andreasen <esbena@github.com>
|
2020-02-24 11:58:59 +01:00 |
|
Erik Krogh Kristensen
|
44db0f4e5d
|
better printing of the options arg
|
2020-02-21 15:39:49 +01:00 |
|
Asger Feldthaus
|
d1df251b92
|
JS: Proto pollution: Add is-plain-object sanitizer
|
2020-02-21 14:38:33 +00:00 |
|
Erik Krogh Kristensen
|
90e5671d98
|
Merge branch 'master' of git.semmle.com:Semmle/ql into CVE481
|
2020-02-21 15:25:07 +01:00 |
|
Asger Feldthaus
|
a673539c98
|
JS: Update expected output
|
2020-02-21 13:51:23 +00:00 |
|
Asger Feldthaus
|
b780bc4d59
|
JS: Also track into callbacks
|
2020-02-21 13:51:22 +00:00 |
|