Max Schaefer
|
725059deea
|
JavaScript: Remove --source-type module extractor options.
|
2019-11-06 13:01:59 +00:00 |
|
Max Schaefer
|
3ad5af7cef
|
JavaScript: Move --extract-program-text extractor options into options files.
|
2019-11-06 13:01:55 +00:00 |
|
Max Schaefer
|
6b817203fd
|
JavaScript: Move --tolerate-parse-errors extractor options into options file.
|
2019-11-06 13:01:28 +00:00 |
|
Max Schaefer
|
5681565d4a
|
JavaScript: Move --html elements extractor options into options file.
|
2019-11-06 13:01:28 +00:00 |
|
Max Schaefer
|
8fdf6298b9
|
JavaScript: Remove --platform node extractor options.
|
2019-11-06 13:01:28 +00:00 |
|
Max Schaefer
|
4848372435
|
JavaScript: Replace --externs extractor flag with /** @externs */ comment.
|
2019-11-06 13:01:28 +00:00 |
|
Max Schaefer
|
1fa8c43a8c
|
JavaScript: Remove a redundant extractor option.
|
2019-11-06 13:01:28 +00:00 |
|
Max Schaefer
|
79f1079460
|
JavaScript: Add options files with --experimental extractor options.
|
2019-11-06 13:01:23 +00:00 |
|
Max Schaefer
|
a4bf361f64
|
JavaScript: Remove remaining --experimental extractor options.
|
2019-11-06 12:54:44 +00:00 |
|
Asger F
|
81723ab92a
|
JS: Update GlobalAccessPaths test
|
2019-11-06 11:58:06 +00:00 |
|
Asger F
|
bc35f24f31
|
JS: Generalize access paths to arbitrary root nodes
|
2019-11-06 11:58:06 +00:00 |
|
semmle-qlci
|
04f0c22f24
|
Merge pull request #2203 from erik-krogh/ignorePureFunction
Approved by max-schaefer, mchammer01
|
2019-11-06 09:09:11 +00:00 |
|
Max Schaefer
|
3e92d0ffb5
|
JavaScript: Remove redundant --experimental extractor options.
|
2019-11-05 15:59:24 +00:00 |
|
Erik Krogh Kristensen
|
16b63b3d01
|
move deferred model to the query where it is used
|
2019-11-05 15:45:17 +01:00 |
|
Erik Krogh Kristensen
|
7045cd2648
|
Merge remote-tracking branch 'upstream/master' into deferredModel
|
2019-11-05 15:08:47 +01:00 |
|
semmle-qlci
|
794d5bda6d
|
Merge pull request #2116 from erik-krogh/arrayCBRet
Approved by max-schaefer
|
2019-11-05 11:32:13 +00:00 |
|
Asger F
|
c373be0dee
|
JS: Update TaintBarriers test
|
2019-11-05 10:26:04 +00:00 |
|
Asger F
|
d8ac0abb7f
|
JS: Add test
|
2019-11-05 10:06:21 +00:00 |
|
semmle-qlci
|
eb6e8866fa
|
Merge pull request #2247 from max-schaefer/odasa-8149
Approved by asger-semmle, esbena
|
2019-11-05 09:40:54 +00:00 |
|
Max Schaefer
|
770a4703c9
|
Merge pull request #2237 from asger-semmle/typescript3.7-rc
TS: Add support for TypeScript 3.7
|
2019-11-04 16:36:11 +00:00 |
|
Esben Sparre Andreasen
|
7f55e3f336
|
JS: classify Doxygen-generated files as "generated"
|
2019-11-04 09:57:41 +01:00 |
|
Asger F
|
79dbdac8fa
|
TS: Support declare modifier for fields
|
2019-11-04 07:54:38 +00:00 |
|
Asger F
|
341c11523c
|
TS: Add recursive type alias tests (already works)
|
2019-11-04 07:54:38 +00:00 |
|
Asger F
|
b81931e402
|
TS: Support assertion types
|
2019-11-04 07:54:38 +00:00 |
|
Asger F
|
f50f3b48c4
|
TS: Add test for ?? operator (already works)
|
2019-11-04 07:54:38 +00:00 |
|
Asger F
|
869fe4558f
|
TS: Support optional chaining
|
2019-11-04 07:54:38 +00:00 |
|
Asger F
|
f76006e490
|
JS: Delete duplicate test case (typo)
|
2019-11-04 07:54:38 +00:00 |
|
Asger F
|
36b6c32f4f
|
TS: Update expected output
|
2019-11-04 07:54:37 +00:00 |
|
Asger F
|
f48d16fcb7
|
JS: Support barrier guards that are reflective calls
|
2019-11-01 15:23:38 +00:00 |
|
Asger F
|
e2b0ec5696
|
JS: Handle multiple and/or operators in SanitizerFunction
|
2019-11-01 15:23:38 +00:00 |
|
semmle-qlci
|
e8e2f7bb20
|
Merge pull request #2240 from max-schaefer/js/indirect-command-argument-data-flow
Approved by esbena
|
2019-11-01 11:00:22 +00:00 |
|
semmle-qlci
|
d03aecaa98
|
Merge pull request #2235 from max-schaefer/js/issue-2233
Approved by esbena
|
2019-10-31 14:17:58 +00:00 |
|
Max Schaefer
|
8aae1f443f
|
JavaScript: Use type tracking instead of auxiliary data-flow configuration to track indirect command arguments.
|
2019-10-31 12:13:55 +00:00 |
|
Max Schaefer
|
311cbd824c
|
JavaScript: Recognize ":" pseudo-directive.
|
2019-10-31 11:39:09 +00:00 |
|
semmle-qlci
|
2a3980222b
|
Merge pull request #2201 from max-schaefer/js/avoid-duplicate-source-and-sink-nodes
Approved by asger-semmle
|
2019-10-31 10:47:30 +00:00 |
|
Max Schaefer
|
bb0771b36c
|
JavaScript: Deal with escape-unescape-escape (and similar) chains.
|
2019-10-30 14:49:01 +00:00 |
|
Max Schaefer
|
8c133ff61d
|
JavaScript: Deal with (un-)escaping on captured variables.
|
2019-10-30 14:46:50 +00:00 |
|
Max Schaefer
|
a8214ce7ee
|
JavaScript: Fix regexes for escaping schemes.
|
2019-10-30 14:15:59 +00:00 |
|
Max Schaefer
|
5349e0f881
|
JavaScript: Recognise wrapped chains of replacements.
|
2019-10-30 13:14:38 +00:00 |
|
Max Schaefer
|
02d16b1dc9
|
JavaScript: Recognise wrapped string replacement functions.
|
2019-10-30 13:01:17 +00:00 |
|
Max Schaefer
|
aaeca32519
|
JavaScript: Recognize string escaping using .replace with a callback.
|
2019-10-30 12:45:32 +00:00 |
|
Max Schaefer
|
bd1c99d8a4
|
JavaScript: Recognise JSON.stringify and JSON.parse as escaper/unescaper.
|
2019-10-30 12:38:05 +00:00 |
|
semmle-qlci
|
a778efe71e
|
Merge pull request #2216 from asger-semmle/xss-encodeURIComponent
Approved by max-schaefer
|
2019-10-30 11:49:31 +00:00 |
|
Max Schaefer
|
b42026a90a
|
JavaScript: Update expected output.
|
2019-10-29 15:36:24 +00:00 |
|
Max Schaefer
|
dc1d1c2f22
|
JavaScript: Update expected output.
|
2019-10-29 15:30:06 +00:00 |
|
Max Schaefer
|
6964945c74
|
JavaScript: Restrict edges to only contain nodes.
|
2019-10-29 15:03:52 +00:00 |
|
semmle-qlci
|
2cddb82f10
|
Merge pull request #2210 from max-schaefer/js/better-destructuring-type-inference
Approved by asger-semmle, esbena
|
2019-10-29 08:08:51 +00:00 |
|
Asger F
|
94dd9a1c04
|
JS: Block XSS flow through encodeURIComponent
|
2019-10-28 17:12:40 +00:00 |
|
semmle-qlci
|
33374ee089
|
Merge pull request #2202 from asger-semmle/express-sendfile
Approved by esbena
|
2019-10-28 09:24:34 +00:00 |
|
Max Schaefer
|
b333c6a214
|
Merge pull request #2106 from asger-semmle/call-graph-3
JS: Call graph changes
|
2019-10-28 09:24:10 +00:00 |
|