Anders Schack-Mulligen
|
ca45fb5a60
|
JavaScript: Autoformat.
|
2019-09-06 09:04:51 +02:00 |
|
Asger F
|
9f1617a6a8
|
JS: Update TaintedPath.expected (4x paths)
|
2019-05-28 11:22:08 +01:00 |
|
Asger F
|
37fa2446d4
|
JS: review comments
|
2019-05-23 10:16:31 +01:00 |
|
Asger F
|
07d508d1bf
|
JS: Track taint through .replace()
|
2019-05-23 09:23:48 +01:00 |
|
Asger F
|
1ec3475457
|
JS: All of TaintedPath
|
2019-05-23 09:23:47 +01:00 |
|
Max Schaefer
|
4533e1f6fe
|
JavaScript: Add model of adm-zip library for ZipSlip query.
|
2019-03-21 08:04:06 +00:00 |
|
Jason Reed
|
4475dd4b9f
|
JavaScript: Add test and fix change note.
|
2019-03-15 14:40:48 -04:00 |
|
Jason Reed
|
6589813ec7
|
JavaScript: Add tar-stream extraction to ZipSlip query.
|
2019-03-15 09:31:26 -04:00 |
|
Max Schaefer
|
48c0949705
|
Merge pull request #1036 from asger-semmle/hide-implicit-ssa-defs
JS: Omit uninteresting nodes from path explanations
|
2019-03-06 13:30:11 +00:00 |
|
Jason Reed
|
8829fde86b
|
JS: Add test for zipslip basename sanitization.
|
2019-03-06 09:46:41 +00:00 |
|
Asger F
|
50a77ea843
|
JS: update test expectations
|
2019-03-06 08:41:03 +00:00 |
|
Jason Reed
|
c5e57dacf8
|
JS: Actually use fileName in examples
|
2019-02-28 15:46:14 -05:00 |
|
Jason Reed
|
b0636dd410
|
JS: Better local flow through .pipe chaining
|
2019-02-28 15:45:33 -05:00 |
|
Jason Reed
|
23d37c7167
|
JS: Unbreak TaintedPath
|
2019-02-28 15:45:26 -05:00 |
|
Jason Reed
|
baa4f08259
|
JS: Add new query for ZipSlip (CWE-022)
|
2019-02-28 15:45:08 -05:00 |
|
Esben Sparre Andreasen
|
305a249280
|
JS: add taint steps for fs.realpath and fs.realpathSync
|
2019-02-21 09:48:35 +01:00 |
|
Esben Sparre Andreasen
|
c57f8a6d6e
|
Merge pull request #691 from asger-semmle/sendfile-root
JS: Recognize 'root' option in Express res.sendFile
|
2018-12-19 16:06:15 +01:00 |
|
Asger F
|
ce18aca62b
|
JS: update expected output
|
2018-12-19 11:30:46 +00:00 |
|
Asger F
|
0e40717358
|
JS: recognize res.sendfile root option
|
2018-12-19 10:25:15 +00:00 |
|
Asger F
|
f84301e476
|
JS: add tests with res.sendFile root option
|
2018-12-19 10:25:15 +00:00 |
|
Max Schaefer
|
9221b62ded
|
JavaScript: Update expectd test output for security path queries to include nodes and edges query predicates.
|
2018-11-14 09:32:31 +00:00 |
|
Asger F
|
6f109a742f
|
JS: add a test case for res.sendfile
|
2018-09-21 11:04:33 +01:00 |
|
Asger F
|
d9ba5a1cab
|
JavaScript: add test cases for new array steps
|
2018-08-13 12:27:12 +01:00 |
|
Asger F
|
b00938e9b3
|
Make NodeJSLib use moduleMember for ES6-compatibility
|
2018-08-09 15:10:21 +01:00 |
|
Pavel Avgustinov
|
b55526aa58
|
QL code and tests for C#/C++/JavaScript.
|
2018-08-02 17:53:23 +01:00 |
|