semmle-qlci
|
1313821a25
|
Merge pull request #1904 from erik-semmle/passportModel
Approved by asger-semmle, esben-semmle
|
2019-09-13 10:38:14 +01:00 |
|
Esben Sparre Andreasen
|
9aa0e711b2
|
JS: update expected output
|
2019-09-11 12:33:41 +02:00 |
|
Esben Sparre Andreasen
|
ee106ccff9
|
JS: simplify asExpr().getStringValue() calls
|
2019-09-11 10:56:57 +02:00 |
|
Esben Sparre Andreasen
|
aab17850d1
|
JS: eliminate redundant ConstantString casts
|
2019-09-11 10:56:49 +02:00 |
|
Erik Krogh Kristensen
|
3ebe6608c2
|
updated expected values for the Express test
|
2019-09-09 13:02:35 +01:00 |
|
erik-semmle
|
d01f84f015
|
fix comment in passport test
Co-Authored-By: Esben Sparre Andreasen <42067045+esben-semmle@users.noreply.github.com>
|
2019-09-09 12:59:38 +01:00 |
|
semmle-qlci
|
2283195ebd
|
Merge pull request #1871 from asger-semmle/type-tracking-through-imports
Approved by xiemaisi
|
2019-09-09 12:25:06 +01:00 |
|
Erik Krogh Kristensen
|
26f6b1d186
|
add model for passport.use in the Express model
|
2019-09-09 12:01:11 +01:00 |
|
Asger F
|
65862c922c
|
JS: Update tests
|
2019-09-09 10:53:13 +01:00 |
|
Asger F
|
631ff27d31
|
JS: Use ValueNode for all ImportSpecifiers
|
2019-09-09 10:53:13 +01:00 |
|
Asger F
|
3b962dce22
|
JS: Add explicit type tracking test
|
2019-09-09 10:51:21 +01:00 |
|
Asger F
|
afcdc12e7b
|
JS: Use ValueNode, not SSA node, to model NamedImportSpecifier
|
2019-09-09 10:51:17 +01:00 |
|
Esben Sparre Andreasen
|
6dbe827dd3
|
JS: add QL classes for the extraction metrics
|
2019-09-09 09:05:12 +02:00 |
|
Anders Schack-Mulligen
|
ca45fb5a60
|
JavaScript: Autoformat.
|
2019-09-06 09:04:51 +02:00 |
|
semmle-qlci
|
33329f95c2
|
Merge pull request #1874 from asger-semmle/express-types
Approved by esben-semmle, xiemaisi
|
2019-09-05 16:42:28 +01:00 |
|
semmle-qlci
|
fd2e8486e4
|
Merge pull request #1862 from asger-semmle/prototype-pollution-angular-merge
Approved by esben-semmle
|
2019-09-05 12:50:58 +01:00 |
|
semmle-qlci
|
e6bfe2bd5d
|
Merge pull request #1873 from asger-semmle/type-inf-consistency
Approved by xiemaisi
|
2019-09-05 12:46:59 +01:00 |
|
Asger F
|
27567e41c5
|
JS: Add angular.fromJson as JSON parser
|
2019-09-04 16:14:51 +01:00 |
|
Asger F
|
9f8bf90424
|
JS: Update Express test
|
2019-09-04 11:43:21 +01:00 |
|
Asger F
|
c06fd451d6
|
JS: Handle router chaining in type tracking predicate
|
2019-09-04 11:43:21 +01:00 |
|
semmle-qlci
|
e4d59c361a
|
Merge pull request #1856 from asger-semmle/ts-base-types
Approved by xiemaisi
|
2019-09-03 10:12:30 +01:00 |
|
Asger F
|
2006826101
|
JS: Avoid breaking local object analysis
|
2019-09-02 16:45:06 +01:00 |
|
Asger F
|
9f2f10fa15
|
JS: Make type inference flow go through ssa definition node
|
2019-09-02 16:45:06 +01:00 |
|
Asger F
|
8737dbb73d
|
JS: Add test
|
2019-09-02 14:31:40 +01:00 |
|
Max Schaefer
|
91e46cd6fd
|
JavaScript: Fix parsing of asynchronous generator methods.
|
2019-09-02 09:56:42 +01:00 |
|
Asger F
|
1b6cc4ebcc
|
JS: Update test
|
2019-08-30 18:19:19 +01:00 |
|
Asger F
|
1e5f0a4e2f
|
JS: Update DataFlow tests
|
2019-08-30 18:19:19 +01:00 |
|
Asger F
|
5512846e6f
|
JS: Update TypeTracking test
|
2019-08-30 18:19:19 +01:00 |
|
Asger F
|
bd6768e2c8
|
JS: Fix closure namespace prefix and update tests
|
2019-08-30 18:19:19 +01:00 |
|
Asger F
|
313579c258
|
JS: Restrict flow to access paths assigned in a unique file
|
2019-08-30 18:19:18 +01:00 |
|
Asger F
|
48b70c4f1d
|
JS: Add type-tracking test case
|
2019-08-30 18:19:18 +01:00 |
|
Asger F
|
f219598281
|
JS: Update DeclarationFiles test
|
2019-08-30 16:02:42 +01:00 |
|
Asger F
|
fa3532ca8c
|
TS: Handle locally defined packages
|
2019-08-30 16:02:42 +01:00 |
|
Asger F
|
d8cda5e268
|
JS: Add Firebase test with types
|
2019-08-30 16:02:41 +01:00 |
|
semmle-qlci
|
fc59dd6819
|
Merge pull request #1788 from asger-semmle/additional-type-tracking-step
Approved by xiemaisi
|
2019-08-24 11:55:16 +01:00 |
|
Asger F
|
45d4b83fc8
|
TS: Extract type args to tagged template exprs
|
2019-08-22 18:07:29 +01:00 |
|
Asger F
|
fd7cfedf4b
|
JS: Add AdditionalTypeTrackingStep
|
2019-08-21 13:44:03 +01:00 |
|
semmle-qlci
|
6c3d1d676b
|
Merge pull request #1694 from asger-semmle/concatenation-operand
Approved by xiemaisi
|
2019-08-08 12:41:30 +01:00 |
|
Asger F
|
5e87d5c751
|
JS: Update syntactic heuristics
|
2019-08-07 10:53:17 +01:00 |
|
Asger F
|
f173e3024a
|
JS: Add getConstantStringParts() and HTML concat node
|
2019-08-07 10:53:17 +01:00 |
|
Asger F
|
f101944c92
|
JS: Expand on the StringOps::Concatenation API
|
2019-08-07 10:53:17 +01:00 |
|
Asger F
|
2df0b08b26
|
JS: Add test with header access
|
2019-08-06 15:43:39 +01:00 |
|
Asger F
|
c4006be0e8
|
JS: Add more axios tests
|
2019-08-06 15:28:53 +01:00 |
|
Asger F
|
af7b942eec
|
JS: Add newline in test
|
2019-08-06 15:28:53 +01:00 |
|
Asger F
|
4fb3fd992d
|
JS: Address comments
|
2019-08-06 15:28:53 +01:00 |
|
Asger F
|
7fb6615970
|
JS: Test for XhrIo
|
2019-08-06 15:28:53 +01:00 |
|
Asger F
|
4eb072a376
|
JS: Test for 'superagent' package
|
2019-08-06 15:28:53 +01:00 |
|
Asger F
|
ce4f098625
|
JS: Test for 'got' package
|
2019-08-06 15:28:52 +01:00 |
|
Asger F
|
f88a7162c5
|
JS: Test for fetch
|
2019-08-06 15:28:52 +01:00 |
|
Asger F
|
b8c1714ba9
|
JS: Test for 'axios' package
|
2019-08-06 15:28:52 +01:00 |
|