semmle-qlci
|
696d19cb14
|
Merge pull request #3773 from erik-krogh/guardedCrypto
Approved by asgerf
|
2020-06-24 13:04:04 +01:00 |
|
semmle-qlci
|
a723ac0d8e
|
Merge pull request #3767 from esbena/js/console-member-calls
Approved by erik-krogh
|
2020-06-24 08:03:49 +01:00 |
|
Erik Krogh Kristensen
|
3f8881a334
|
don't report insecure randomness when the insecure random is just a fallback
|
2020-06-23 15:53:19 +02:00 |
|
semmle-qlci
|
0d61443915
|
Merge pull request #3753 from asger-semmle/js/xss-dom-exception-rephrasing
Approved by erik-krogh
|
2020-06-23 13:01:41 +01:00 |
|
Asger Feldthaus
|
4f67cc269b
|
JS: Reduce ExpansiveTypes test
|
2020-06-23 11:44:07 +01:00 |
|
Asger Feldthaus
|
234f968294
|
JS: Deprecate property lookup on types
|
2020-06-23 11:42:28 +01:00 |
|
Esben Sparre Andreasen
|
2d32ee7448
|
JS: support member calls of console
|
2020-06-23 10:46:01 +02:00 |
|
Asger Feldthaus
|
b4f75ef414
|
Merge branch 'master' into js-team-sprint-merge2
|
2020-06-23 00:18:09 +01:00 |
|
Esben Sparre Andreasen
|
9a0bbb31f4
|
Revert "Merge pull request #3702 from esbena/js/memory-exhaustion"
This reverts commit eca5e2df8a, reversing
changes made to 1548eca994.
|
2020-06-22 14:46:51 +02:00 |
|
Esben Sparre Andreasen
|
0a8d15ccc4
|
Revert "Merge pull request #3672 from esbena/js/server-crashing-route-handler"
This reverts commit 243e3ad9e3, reversing
changes made to df79f2adc5.
|
2020-06-22 14:45:35 +02:00 |
|
Asger Feldthaus
|
1edb2a1892
|
JS: Rephrase XSS queries that use exception/dom text as source
|
2020-06-22 10:44:46 +01:00 |
|
Asger F
|
eca5e2df8a
|
Merge pull request #3702 from esbena/js/memory-exhaustion
JS: add query js/memory-exhaustion
|
2020-06-19 20:35:57 +01:00 |
|
Erik Krogh Kristensen
|
0f5ef2c02a
|
Merge branch 'js-team-sprint' into https-fix
|
2020-06-19 14:57:44 +02:00 |
|
Erik Krogh Kristensen
|
0ee3f4977c
|
add test of webpack-dev-server and monorepo import
|
2020-06-19 14:15:46 +02:00 |
|
Erik Krogh Kristensen
|
11cc97d286
|
add basic support for importing from neighbouring packages
|
2020-06-19 14:15:10 +02:00 |
|
Erik Krogh Kristensen
|
a17d152ca4
|
Merge branch 'js-team-sprint' into priv-file-polish
|
2020-06-19 13:19:10 +02:00 |
|
Erik Krogh Kristensen
|
7d6dac479c
|
Merge branch 'js-team-sprint' into https-fix
|
2020-06-18 16:53:01 +02:00 |
|
Erik Krogh Kristensen
|
dcf617b235
|
Merge branch 'js-team-sprint' into bad-random-polish
|
2020-06-18 16:52:32 +02:00 |
|
Erik Krogh Kristensen
|
1556b62007
|
Merge branch 'js-team-sprint' into priv-file-polish
|
2020-06-18 16:40:53 +02:00 |
|
Esben Sparre Andreasen
|
3f67e90374
|
JS: rename query, support timeouts, add documentation, add to suite
|
2020-06-18 13:01:02 +02:00 |
|
Esben Sparre Andreasen
|
d9d8eb4805
|
JS: avoid type inference in the taint steps (just a nice to have)
|
2020-06-18 13:00:45 +02:00 |
|
Esben Sparre Andreasen
|
7b97fd07a8
|
JS: add query js/memory-exhaustion
|
2020-06-18 13:00:45 +02:00 |
|
Erik Krogh Kristensen
|
7a1c161e9e
|
Merge branch 'js-team-sprint' into https-fix
|
2020-06-17 21:04:44 +02:00 |
|
Erik Krogh Kristensen
|
218338b4f1
|
Merge branch 'js-team-sprint' into bad-random-polish
|
2020-06-17 21:04:00 +02:00 |
|
Erik Krogh Kristensen
|
73f26956a6
|
Merge branch 'js-team-sprint' into priv-file-polish
|
2020-06-17 21:03:09 +02:00 |
|
Erik Krogh Kristensen
|
bdda587247
|
Merge branch 'js-team-sprint' into build-leaks
|
2020-06-17 19:51:30 +02:00 |
|
Erik Krogh Kristensen
|
cd111fe350
|
Merge pull request #3721 from asger-semmle/js/non-linear-pattern-msg
JS: Improve alert message in js/non-linear-pattern
|
2020-06-17 13:10:56 +02:00 |
|
Erik Krogh Kristensen
|
fa0a8c3423
|
add documentation examples as tests
|
2020-06-17 11:37:32 +02:00 |
|
Erik Krogh Kristensen
|
639907967f
|
add home/rootdir as leaking folders
|
2020-06-17 10:46:42 +02:00 |
|
Erik Krogh Kristensen
|
6675ddae12
|
add more libraries that serve static files to js/exposure-of-private-files
|
2020-06-17 10:00:59 +02:00 |
|
Erik Krogh Kristensen
|
210e71cd93
|
update expected output
|
2020-06-16 21:52:59 +02:00 |
|
Erik Krogh Kristensen
|
5ce17bea60
|
add qhelp for js/bad-code-sanitization
|
2020-06-16 16:23:41 +02:00 |
|
Erik Krogh Kristensen
|
a0951f76b6
|
add additional taint steps when type-tracking RemoteFlowSource
|
2020-06-16 14:55:07 +02:00 |
|
semmle-qlci
|
07bff646d8
|
Merge pull request #3641 from asger-semmle/js/pre-call-graph-steps
Approved by erik-krogh
|
2020-06-16 13:41:55 +01:00 |
|
Erik Krogh Kristensen
|
696879653a
|
add qhelp to js/biased-cryptographic-random
|
2020-06-16 11:10:09 +02:00 |
|
Asger Feldthaus
|
3242f5ed94
|
JS: Include qhelp example in test suite
|
2020-06-15 17:37:26 +01:00 |
|
Asger Feldthaus
|
7091a9f704
|
JS: Special-case alert message for type annotations
|
2020-06-15 17:17:47 +01:00 |
|
Asger Feldthaus
|
c8ab69af11
|
JS: Avoid duplicate alerts
|
2020-06-15 16:57:54 +01:00 |
|
Asger Feldthaus
|
f380898126
|
JS: Add test showing duplicate alerts
|
2020-06-15 16:40:37 +01:00 |
|
Asger Feldthaus
|
51d143d6f1
|
JS: Add test with destructuring pattern that looks like type annotations
|
2020-06-15 16:35:36 +01:00 |
|
Erik Krogh Kristensen
|
3ef5dc74a1
|
add backtracking to find division that end up being rounded
|
2020-06-15 17:10:10 +02:00 |
|
semmle-qlci
|
3728e1afd3
|
Merge pull request #3715 from asger-semmle/js/returned-functions
Approved by erik-krogh, esbena
|
2020-06-15 15:32:54 +01:00 |
|
Asger Feldthaus
|
17010e25a1
|
JS: Update another test
|
2020-06-15 13:55:46 +01:00 |
|
semmle-qlci
|
57c8dd85a4
|
Merge pull request #2801 from esbena/js/bulky-route-handler-registration
Approved by asgerf
|
2020-06-15 13:06:22 +01:00 |
|
Asger Feldthaus
|
c4179eb81d
|
JS: Update test
|
2020-06-15 11:13:20 +01:00 |
|
semmle-qlci
|
b6b838774e
|
Merge pull request #3704 from asger-semmle/js/cve-serve
Approved by esbena
|
2020-06-15 09:54:17 +01:00 |
|
Asger Feldthaus
|
315f3389d1
|
JS: Autoformat test
|
2020-06-12 19:58:05 +01:00 |
|
Asger F
|
d844e0025a
|
Merge pull request #3651 from esbena/js/bad-multicharacter-sanitization
JS: initial version of IncompleteMultiCharacterSanitization.ql
|
2020-06-12 16:25:22 +01:00 |
|
Asger Feldthaus
|
5548606f21
|
JS: Add test
|
2020-06-12 13:02:33 +01:00 |
|
Erik Krogh Kristensen
|
01c51eea89
|
Merge pull request #3680 from erik-krogh/bad-code-sanitizer
JS: Add query to detect bad code sanitizers
|
2020-06-12 14:00:21 +02:00 |
|