CodeQL CI
|
0753c8a31b
|
Merge pull request #4247 from erik-krogh/CVE760-reexport
Approved by asgerf
|
2020-10-06 06:10:21 -07:00 |
|
CodeQL CI
|
ef703e72d8
|
Merge pull request #4401 from asgerf/js/angular-prerequisites
Approved by erik-krogh
|
2020-10-06 06:09:48 -07:00 |
|
CodeQL CI
|
7e6fa7b4be
|
Merge pull request #4392 from erik-krogh/flask
Approved by asgerf
|
2020-10-06 03:41:36 -07:00 |
|
Erik Krogh Kristensen
|
f7f82ffe4e
|
Merge branch 'main' into CVE760-reexport
|
2020-10-06 12:28:44 +02:00 |
|
CodeQL CI
|
bc1d3de8fe
|
Merge pull request #4376 from erik-krogh/simpParam
Approved by asgerf
|
2020-10-06 03:24:43 -07:00 |
|
Erik Krogh Kristensen
|
99213b94f5
|
detect uses of jsxFactory and jsxFragmentFactory in js/unused-local-variable
|
2020-10-06 12:23:15 +02:00 |
|
Asger Feldthaus
|
c31cdaacb2
|
JS: Add test for getFieldTypeAnnotation
|
2020-10-06 10:01:04 +01:00 |
|
Max Schaefer
|
8277d5c08f
|
JavaScript: Introduce convenience predicate for working with typed API-graph nodes.
|
2020-10-06 09:25:35 +01:00 |
|
Max Schaefer
|
9206549a38
|
JavaScript: Make integration of TypeScript canonical names with modules in API graphs more consistent.
Previously, canonical names were direct successors of module definitions/uses, now they are successors of exports/imports.
|
2020-10-06 09:25:35 +01:00 |
|
Erik Krogh Kristensen
|
d6dc4bb655
|
allow flask url_for urls in TargetBlank.ql
|
2020-10-05 21:40:24 +02:00 |
|
Erik Krogh Kristensen
|
7d8bb339b6
|
add support for destructuring object exports in getAnExportedValue
|
2020-10-05 21:38:31 +02:00 |
|
CodeQL CI
|
e95b665556
|
Merge pull request #4363 from erik-krogh/nosql-api
Approved by max-schaefer
|
2020-10-05 12:01:34 -07:00 |
|
CodeQL CI
|
43b2c90538
|
Merge pull request #4400 from max-schaefer/js/api-graph-classrefs
Approved by asgerf
|
2020-10-05 03:12:23 -07:00 |
|
Erik Krogh Kristensen
|
abdbe92720
|
refactor the NoSQL model to use API graphs
|
2020-10-02 10:42:49 +02:00 |
|
Max Schaefer
|
98e93a7b9d
|
JavaScript: Improve API-graph support for function-style classes.
|
2020-10-02 09:25:51 +01:00 |
|
Aditya Sharad
|
f7f05476a2
|
Merge pull request #4375 from adityasharad/javascript/client-side-url-redirect-regexp
JavaScript: Track taint through RegExp.prototype.exec for URL redirection
|
2020-10-01 09:55:19 -07:00 |
|
CodeQL CI
|
36450a8998
|
Merge pull request #4338 from erik-krogh/nodejs-server-request-data
Approved by asgerf
|
2020-10-01 06:00:17 -07:00 |
|
Erik Krogh Kristensen
|
18f7f2b559
|
autoformat
|
2020-10-01 13:49:31 +02:00 |
|
Erik Krogh Kristensen
|
4dec2171da
|
add http request server data as a RemoteFlowSource
|
2020-10-01 13:21:56 +02:00 |
|
CodeQL CI
|
0158e2ffef
|
Merge pull request #4374 from max-schaefer/js/api-graph
Approved by erik-krogh
|
2020-10-01 03:33:45 -07:00 |
|
Erik Krogh Kristensen
|
75b9237b81
|
use Parameter instead of SimpleParameter in the AngularJS model
|
2020-10-01 10:44:10 +02:00 |
|
Erik Krogh Kristensen
|
c675d72629
|
use Parameter instead of SimpleParameter in remaining route-handler models
|
2020-10-01 10:44:10 +02:00 |
|
Erik Krogh Kristensen
|
f65ba11485
|
use Parameter instead of SimpleParameter in AMD.qll
|
2020-10-01 10:44:05 +02:00 |
|
Aditya Sharad
|
e712d16e7e
|
JavaScript: Track taint through RegExp.prototype.exec for URL redirection
Regexp literals are currently handled, but not `RegExp` objects.
|
2020-09-30 15:13:02 -07:00 |
|
Erik Krogh Kristensen
|
d316cb512e
|
deprecate exports and replace uses with the new getAnExportedValue
|
2020-09-30 13:46:28 +02:00 |
|
Erik Krogh Kristensen
|
adc05022f3
|
update comment in test case
Co-authored-by: Max Schaefer <54907921+max-schaefer@users.noreply.github.com>
|
2020-09-29 18:21:41 +02:00 |
|
Erik Krogh Kristensen
|
3857331657
|
avoid .getReturn().getAUse().(DataFlow::InvokeNode) in the SQL model
|
2020-09-29 17:08:09 +02:00 |
|
CodeQL CI
|
d7add29dc2
|
Merge pull request #4359 from erik-krogh/cookieWrites
Approved by esbena
|
2020-09-29 06:32:01 -07:00 |
|
CodeQL CI
|
910c19e613
|
Merge pull request #4348 from erik-krogh/needle
Approved by esbena
|
2020-09-29 02:57:32 -07:00 |
|
CodeQL CI
|
11f39a9d88
|
Merge pull request #4342 from erik-krogh/track-where-prop
Approved by asgerf
|
2020-09-29 02:09:53 -07:00 |
|
Erik Krogh Kristensen
|
e04404b713
|
also recognize cookie writes are leading to cookie access
|
2020-09-28 21:17:25 +02:00 |
|
Max Schaefer
|
dfc4436012
|
JavaScript: Teach API graphs to recognise arguments supplied in partial function applications.
|
2020-09-28 17:52:57 +01:00 |
|
Erik Krogh Kristensen
|
664342dd0f
|
change SimpleParameter to Parameter in the express model to support destructuring parameters
|
2020-09-26 21:31:06 +02:00 |
|
CodeQL CI
|
ea5feb2b0a
|
Merge pull request #4331 from erik-krogh/DVNA-files
Approved by esbena
|
2020-09-25 05:21:03 -07:00 |
|
Erik Krogh Kristensen
|
6b9aea82ca
|
model method calls in the needle library
|
2020-09-25 14:13:31 +02:00 |
|
Erik Krogh Kristensen
|
a22ddb145b
|
model calls to needle
|
2020-09-25 13:53:22 +02:00 |
|
Erik Krogh Kristensen
|
b8154d41b1
|
type-track objects where the "$where" property has been written
|
2020-09-24 20:55:25 +02:00 |
|
Erik Krogh Kristensen
|
6163e6cf5f
|
adjust test case for XML entity expansion
|
2020-09-24 09:53:06 +02:00 |
|
Erik Krogh Kristensen
|
83f0514475
|
add req.files as a RequestInputAccess in the Express model
|
2020-09-23 15:50:59 +02:00 |
|
Max Schaefer
|
dc7b447895
|
JavaScript: Make alert locations for command injection more precise.
|
2020-09-23 14:07:36 +01:00 |
|
Max Schaefer
|
439aadf0b6
|
JavaScript: Do even more type tracking in command injection.
|
2020-09-23 14:07:36 +01:00 |
|
Max Schaefer
|
ef18b39124
|
JavaScript: Fix use of type backtracker in IndirectCommandArgument.qll.
|
2020-09-23 14:07:36 +01:00 |
|
Max Schaefer
|
825fc2228b
|
JavaScript: Add two new command-injection tests.
|
2020-09-23 14:07:36 +01:00 |
|
CodeQL CI
|
9a306866c5
|
Merge pull request #4282 from erik-krogh/es2021
Approved by esbena
|
2020-09-22 05:34:35 -07:00 |
|
Erik Krogh Kristensen
|
4bc91c4439
|
add support for Promise.any
|
2020-09-21 10:50:06 +02:00 |
|
Erik Krogh Kristensen
|
b09015380a
|
add support for String.prototype.replaceAll
|
2020-09-21 10:50:04 +02:00 |
|
Erik Krogh Kristensen
|
b4e75bf567
|
update expected output
|
2020-09-18 09:29:13 +02:00 |
|
Erik Krogh Kristensen
|
1f95311342
|
further loosen the RouteHandlerCandidate heuristic
|
2020-09-18 09:29:13 +02:00 |
|
Erik Krogh Kristensen
|
3eaa56ed60
|
support containers with decorated route handlers
|
2020-09-18 09:29:08 +02:00 |
|
Erik Krogh Kristensen
|
c087e94d47
|
add additional indirect route-handler steps
|
2020-09-18 09:26:33 +02:00 |
|