CodeQL CI
|
fd4e8f8282
|
Merge pull request #5526 from erik-krogh/quotedShell
Approved by esbena
|
2021-04-07 08:39:01 +01:00 |
|
Erik Krogh Kristensen
|
3d49b8cb91
|
consider quoted string concatenations as sanitizers for js/shell-command-injection-from-environment
|
2021-03-25 15:17:02 +01:00 |
|
Erik Krogh Kristensen
|
8949b9eb0a
|
add shell interpreted arrays as sinks for js/shell-command-constructed-from-input
|
2021-03-19 15:59:06 +01:00 |
|
Esben Sparre Andreasen
|
ba714a1214
|
JS: add execa.shell tests
|
2020-12-22 09:01:43 +01:00 |
|
Max Schaefer
|
825fc2228b
|
JavaScript: Add two new command-injection tests.
|
2020-09-23 14:07:36 +01:00 |
|
CodeQL CI
|
a4f8b19ae4
|
Merge pull request #3876 from erik-krogh/CWE078-Correctness
Approved by esbena
|
2020-08-03 15:38:51 +01:00 |
|
Max Schaefer
|
9aa26fa4bc
|
JavaScript: Add model for foreground-child.
>1M weekly downloads, so seems worth doing.
|
2020-07-27 11:37:06 +01:00 |
|
Erik Krogh Kristensen
|
dc8042adeb
|
introduce conistency-checking for CWE-078
|
2020-07-06 12:47:56 +02:00 |
|
Erik Krogh Kristensen
|
c8cf958c8a
|
add test cases for js/shell-command-constructed-from-input
|
2020-05-17 10:32:27 +02:00 |
|
Erik Krogh Kristensen
|
87d283aa6c
|
add tests for third party command execution libraries (and two small fixes)
|
2020-02-25 10:50:59 +01:00 |
|
Erik Krogh Kristensen
|
fb94af9764
|
remove the last dependency on PrettyPrinting
|
2020-02-24 13:18:15 +01:00 |
|
Erik Krogh Kristensen
|
473787a426
|
refactor the getOptionsArg predicate into the SystemCommandExecution class
|
2020-02-24 12:59:20 +01:00 |
|
Erik Krogh Kristensen
|
44db0f4e5d
|
better printing of the options arg
|
2020-02-21 15:39:49 +01:00 |
|
Erik Krogh Kristensen
|
75410e5760
|
big refactor of UselessUseOfCal
|
2020-02-21 14:26:42 +01:00 |
|
Erik Krogh Kristensen
|
b1cbfce50b
|
use SystemCommandExecution and a few small fixes
|
2020-02-20 14:17:37 +01:00 |
|
Erik Krogh Kristensen
|
12c0291dde
|
require that an options object has a known set of properties
|
2020-02-20 11:35:11 +01:00 |
|
Erik Krogh Kristensen
|
b5ef45e6c2
|
add isSync predicate to SystemCommandExecution
|
2020-02-20 11:30:23 +01:00 |
|
Erik Krogh Kristensen
|
a193cb110e
|
support arrow functions in the callbacks
|
2020-02-20 11:13:39 +01:00 |
|
Erik Krogh Kristensen
|
bdab9ee12b
|
change useless cat query to only flag instances that can be re-written to
|
2020-02-19 16:59:28 +01:00 |
|