Asger Feldthaus
|
254ac7f963
|
JS: Fix TypeofCheck
|
2020-12-07 10:46:00 +00:00 |
|
Asger Feldthaus
|
0496642b0b
|
JS: Add test for captured flow into callback
|
2020-12-07 10:34:27 +00:00 |
|
Asger Feldthaus
|
355cfaaf42
|
JS: Autoformat
|
2020-12-07 10:16:39 +00:00 |
|
Asger Feldthaus
|
1b0bec9143
|
JS: Remove magic from barrier guard predicates
|
2020-12-07 10:16:39 +00:00 |
|
Asger Feldthaus
|
fe86465a0b
|
JS: Refactor store/load flow a bit
|
2020-12-07 10:16:38 +00:00 |
|
Asger Feldthaus
|
f132b4a279
|
JS: Add type confusion sink for prototype pollution checks
|
2020-12-07 10:16:38 +00:00 |
|
Asger Feldthaus
|
e10a22ec26
|
JS: Restrict size of some predicates
|
2020-12-07 10:16:38 +00:00 |
|
Asger Feldthaus
|
daab3c1437
|
JS: Add tests and fix some bugs
|
2020-12-07 10:16:38 +00:00 |
|
Asger Feldthaus
|
0a7513fdfb
|
JS: Move and rename test cases as well
|
2020-12-07 10:16:38 +00:00 |
|
Asger Feldthaus
|
479dcf56ad
|
JS: Update to use more inclusive language
|
2020-12-07 10:16:38 +00:00 |
|
Asger Feldthaus
|
ca38a1c8b9
|
JS: Update CWE tags
|
2020-12-07 10:16:38 +00:00 |
|
Asger Feldthaus
|
25161ed338
|
JS: Move all prototype pollution queries to CWE-915
|
2020-12-07 10:16:38 +00:00 |
|
Asger Feldthaus
|
877b4b0752
|
JS: Move and rename other prototype pollution queries
|
2020-12-07 10:16:38 +00:00 |
|
Asger Feldthaus
|
972c4d61e5
|
JS: Add PrototypePollutingAssignment
|
2020-12-07 10:16:38 +00:00 |
|
Asger Feldthaus
|
ef52c46aed
|
JS: Add spread step in TaintedObject
|
2020-12-07 10:16:37 +00:00 |
|
CodeQL CI
|
0f5f0ed99e
|
Merge pull request #4776 from asgerf/js/electron-openshell
Approved by erik-krogh
|
2020-12-04 09:12:44 +00:00 |
|
Asger Feldthaus
|
f0516dd9e0
|
JS: Address review comments
|
2020-12-04 09:07:44 +00:00 |
|
Erik Krogh Kristensen
|
cc98c41dd6
|
revert marking repetitions with possibly empty body as forks
|
2020-12-03 20:08:07 +01:00 |
|
Erik Krogh Kristensen
|
47488f86b5
|
update test
|
2020-12-03 16:58:08 +01:00 |
|
Erik Krogh Kristensen
|
3bad75dae5
|
better support for forms in js/xss-through-dom
|
2020-12-03 16:57:41 +01:00 |
|
Asger Feldthaus
|
20d9848f07
|
JS: Add test case
|
2020-12-03 15:08:43 +00:00 |
|
Asger Feldthaus
|
68d2bc861d
|
JS: Update test expectations
|
2020-12-03 15:01:50 +00:00 |
|
Asger Feldthaus
|
757398f5fd
|
JS: Add upgrade script and stats
|
2020-12-03 13:58:39 +00:00 |
|
Asger Feldthaus
|
3b3052d792
|
JS: Autoformat
|
2020-12-03 13:58:39 +00:00 |
|
Asger Feldthaus
|
5676891e44
|
JS: Add TemplateLiteralTypeExpr
|
2020-12-03 13:58:39 +00:00 |
|
Asger F
|
254072dd6d
|
Merge pull request #4546 from toufik-airane/main
JS: Add ElectronShellOpenExternalSink class for Electron framework security
|
2020-12-03 13:20:46 +00:00 |
|
CodeQL CI
|
edbbc846d0
|
Merge pull request #4753 from max-schaefer/js/more-nosql-query-args
Approved by asgerf, mchammer01
|
2020-12-03 08:46:47 +00:00 |
|
Asger Feldthaus
|
412939d071
|
JS: Autoformat
|
2020-12-02 13:08:32 +00:00 |
|
Asger Feldthaus
|
5561e8f1f6
|
JS: Delete old query and update qhelp
|
2020-12-01 17:05:48 +00:00 |
|
Asger Feldthaus
|
6211fe718b
|
JS: Add test
|
2020-12-01 17:05:48 +00:00 |
|
Asger Feldthaus
|
1459d9197d
|
JS: Adjust alert message for template sinks
|
2020-12-01 17:05:48 +00:00 |
|
Asger Feldthaus
|
8412a6bcbb
|
JS: Add template injection sinks to js/code-injection
|
2020-12-01 17:05:48 +00:00 |
|
Erik Krogh Kristensen
|
c50951cbae
|
add missing qldoc
|
2020-12-01 09:48:35 +01:00 |
|
Erik Krogh Kristensen
|
9a31ed13ac
|
add test case
|
2020-12-01 09:18:40 +01:00 |
|
Erik Krogh Kristensen
|
dea2eb5443
|
simplify the logging sink - using the new API-graph logging models
|
2020-12-01 09:18:40 +01:00 |
|
Erik Krogh Kristensen
|
6f29a877fa
|
move logInjection out of experimental
|
2020-12-01 09:18:40 +01:00 |
|
Erik Krogh Kristensen
|
f6c358861c
|
convert logging models to use API-graphs
|
2020-12-01 09:18:36 +01:00 |
|
Max Schaefer
|
978d2db252
|
JavaScript: Add models for more Mongoose methods.
|
2020-11-30 16:32:13 +00:00 |
|
Anders Schack-Mulligen
|
8f2094f0bf
|
Autoformat.
|
2020-11-30 14:42:38 +01:00 |
|
Erik Krogh Kristensen
|
33b2701551
|
refine isFork to remove false positive when a state has epsilon transition to itself
|
2020-11-29 21:42:50 +01:00 |
|
Erik Krogh Kristensen
|
d7b22e3b1b
|
update expected output for PolynomialBackTracking
|
2020-11-27 20:15:27 +01:00 |
|
Erik Krogh Kristensen
|
729073fb43
|
detect ReDoS when the choices are "match some string" or "match Epsilon"
|
2020-11-27 20:15:23 +01:00 |
|
Erik Krogh Kristensen
|
46ca56458a
|
introduce a printable state class
|
2020-11-27 13:45:41 +01:00 |
|
Erik Krogh Kristensen
|
8a3e87fe42
|
remove unnecessary one-step inline
|
2020-11-27 13:45:41 +01:00 |
|
Erik Krogh Kristensen
|
36b9f0254e
|
performance improvements for suffix check in js/redos
|
2020-11-27 13:45:41 +01:00 |
|
Erik Krogh Kristensen
|
e177d46c0a
|
add two test cases that demonstrate the limits of the suffix construction
|
2020-11-27 13:45:34 +01:00 |
|
Erik Krogh Kristensen
|
fd0d5c9e46
|
add command parsing model for "commander"
|
2020-11-27 09:58:00 +00:00 |
|
Erik Krogh Kristensen
|
653ebf7668
|
add command parsing model for "dashdash"
|
2020-11-27 09:57:05 +00:00 |
|
Erik Krogh Kristensen
|
269de49196
|
add model for "meow"
|
2020-11-27 09:57:05 +00:00 |
|
Erik Krogh Kristensen
|
c5ac98d2e8
|
add command parsing model for command-line-args
|
2020-11-27 09:57:05 +00:00 |
|