Napalys Klicius
|
51b83dbce5
|
Merge pull request #19579 from Napalys/js/dom_property_access
JS: Improve `useless-expression` query to avoid duplicate alerts on compound expressions
|
2025-06-10 15:17:13 +02:00 |
|
Napalys Klicius
|
e46581163a
|
Update javascript/ql/lib/Expressions/ExprHasNoEffect.qll
Co-Authored-By: Asger F <316427+asgerf@users.noreply.github.com>
|
2025-06-10 13:23:31 +02:00 |
|
Napalys Klicius
|
496d8d44eb
|
Update javascript/ql/lib/Expressions/ExprHasNoEffect.qll
Co-authored-by: Asger F <asgerf@github.com>
|
2025-06-10 13:19:48 +02:00 |
|
Napalys Klicius
|
e6f071ce46
|
Update javascript/ql/lib/Expressions/ExprHasNoEffect.qll
Co-authored-by: Asger F <asgerf@github.com>
|
2025-06-10 13:18:48 +02:00 |
|
Napalys Klicius
|
c97da2eda5
|
Exclude expressions that are part of a conditional expression
|
2025-06-10 10:56:11 +02:00 |
|
github-actions[bot]
|
21463a9653
|
Post-release preparation for codeql-cli-2.22.0
|
2025-06-09 18:50:20 +00:00 |
|
github-actions[bot]
|
88ba02edf8
|
Release preparation for version 2.22.0
|
2025-06-09 18:14:51 +00:00 |
|
Chuan-kai Lin
|
631502e129
|
Merge branch 'main' into cklin/rc-3.18-mergeback
|
2025-06-09 07:19:40 -07:00 |
|
Napalys Klicius
|
aac56e089a
|
JavaScript: Fix false positive on Flow type annotations in ExprHasNoEffect
|
2025-06-03 15:26:22 +02:00 |
|
Napalys Klicius
|
46b5ded862
|
JS: Enhance void context propagation
|
2025-06-03 15:20:55 +02:00 |
|
Napalys Klicius
|
bf48b59874
|
JS: Removed exclusion of FunctionExpr from compound statements.
|
2025-06-03 15:12:26 +02:00 |
|
Asger F
|
9ea4410592
|
Merge pull request #19587 from asgerf/js/angular2-client-side
JS: Mark AngularJS $location as client-side remote flow source
|
2025-06-03 13:40:01 +02:00 |
|
Napalys Klicius
|
bca1bc7153
|
JS: Enhance isDomProperty to check for getAPropertyRead on DOM nodes
|
2025-06-02 14:56:45 +02:00 |
|
Napalys Klicius
|
c981c4fe30
|
Update javascript/ql/lib/change-notes/2025-05-30-url-package-taint-step.md
Co-authored-by: Asger F <asgerf@github.com>
|
2025-06-02 13:34:47 +02:00 |
|
Napalys Klicius
|
0b6a747737
|
Added change note
|
2025-05-30 18:33:59 +02:00 |
|
Napalys Klicius
|
b9b62fa1c1
|
JS: Add URL from url package constructor taint step for request forgery detection
|
2025-05-30 18:32:02 +02:00 |
|
github-actions[bot]
|
d2c6875eac
|
Post-release preparation for codeql-cli-2.21.4
|
2025-05-27 18:16:21 +00:00 |
|
github-actions[bot]
|
bfb91e95e3
|
Release preparation for version 2.21.4
|
2025-05-27 17:22:05 +00:00 |
|
Asger F
|
076e4a49d5
|
JS: Mark AngularJS $location as client-side remote flow source
|
2025-05-27 09:47:43 +02:00 |
|
Anders Schack-Mulligen
|
1d30103559
|
SSA: Distinguish between has and controls branch edge.
|
2025-05-23 09:56:22 +02:00 |
|
Asger F
|
1e8a49f311
|
JS: More efficient nested package naming
|
2025-05-19 12:53:18 +02:00 |
|
Napalys Klicius
|
f6a8909bfe
|
Merge pull request #19356 from Napalys/js/merge_classes
JS: Merge `ES6Class` to `FunctionStyleClass`
|
2025-05-16 10:31:33 +02:00 |
|
github-actions[bot]
|
5f9dd75d7d
|
Post-release preparation for codeql-cli-2.21.3
|
2025-05-13 21:49:43 +00:00 |
|
github-actions[bot]
|
2de4a01c86
|
Release preparation for version 2.21.3
|
2025-05-13 21:14:27 +00:00 |
|
Asger F
|
169ae19015
|
Merge pull request #19391 from asgerf/js/typescript-path-resolution
JS: Overhaul import resolution
|
2025-05-13 15:46:38 +02:00 |
|
Asger F
|
aea676df3c
|
Merge pull request #19445 from asgerf/js/summaries-with-fallback
JS: Generate flow summaries from summaryModels; only generate steps as a fallback
|
2025-05-13 14:49:38 +02:00 |
|
Napalys Klicius
|
d1e769ba54
|
Merge pull request #19422 from Napalys/js/shelljs
JS: Modeling of `ShellJS` functions
|
2025-05-02 14:18:44 +02:00 |
|
Napalys Klicius
|
30694c11d6
|
Removed code duplication
|
2025-05-02 13:44:07 +02:00 |
|
Asger F
|
b8be1bcee8
|
JS: Avoid duplication with constructor body
|
2025-05-02 13:44:03 +02:00 |
|
Napalys Klicius
|
871e93d9fe
|
Update javascript/ql/lib/semmle/javascript/frameworks/ShellJS.qll
Co-authored-by: Asger F <asgerf@github.com>
|
2025-05-02 13:39:46 +02:00 |
|
Asger F
|
1f308ee47a
|
JS: Explain use of monotonicAggregates
|
2025-05-02 13:22:27 +02:00 |
|
Asger F
|
5c9218fe5a
|
JS: Add comment about 'path' heuristic
|
2025-05-02 13:22:25 +02:00 |
|
Asger F
|
f3e0cfd947
|
Apply suggestions from code review
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2025-05-02 12:41:29 +02:00 |
|
Napalys Klicius
|
c430a36b4c
|
Refactored merge StandardClassNode into ClassNode
|
2025-05-01 19:12:12 +02:00 |
|
Asger F
|
a44bdf3be2
|
JS: Generate summaries from summaryModel, and only generate steps as a fallback
|
2025-05-01 15:22:47 +02:00 |
|
Asger F
|
ca5f8b0c1d
|
JS: Move some code into ModelsAsData.qll
|
2025-05-01 15:17:07 +02:00 |
|
Napalys Klicius
|
68a9dd9f9e
|
Address comments
|
2025-05-01 11:19:41 +02:00 |
|
Napalys Klicius
|
c7d764f666
|
Brought back FunctionStyleClass marked as deprecated
|
2025-05-01 11:16:04 +02:00 |
|
Napalys Klicius
|
d4b5ef6a66
|
Refactor process.env handling in CleartextLogging and IndirectCommandInjection modules to use ThreatModelSource
|
2025-05-01 11:14:15 +02:00 |
|
Napalys Klicius
|
602500e280
|
Added change note
|
2025-05-01 11:09:56 +02:00 |
|
Napalys Klicius
|
40d176a770
|
Added model for shelljs.env
|
2025-05-01 11:09:47 +02:00 |
|
Napalys Klicius
|
9bab59363c
|
Fix class instance method detection in constructor receiver
|
2025-05-01 09:14:39 +02:00 |
|
Napalys Klicius
|
c0917434eb
|
Removed code duplication
|
2025-05-01 09:14:36 +02:00 |
|
Napalys Klicius
|
fc7520e9e7
|
Added change note
|
2025-05-01 09:14:34 +02:00 |
|
Napalys Klicius
|
7fec3aec95
|
Renamed FunctionStyleClass class to StandardClassNode
|
2025-04-30 18:51:46 +02:00 |
|
Napalys Klicius
|
e9ee7134ef
|
Refactor prototype reference retrieval in ClassNode and update expected test output
|
2025-04-30 18:51:39 +02:00 |
|
Napalys Klicius
|
9624a413e4
|
Added change note
|
2025-04-30 14:57:00 +02:00 |
|
Napalys Klicius
|
71f1b82a56
|
Added support for fastify.all
|
2025-04-30 14:54:09 +02:00 |
|
Asger F
|
8ebbfb198e
|
Merge pull request #19412 from asgerf/js/promise-all
JS: Better type-tracking through Promise.all()
|
2025-04-30 14:19:12 +02:00 |
|
Napalys Klicius
|
18cea2d6a5
|
Added support for shelljs.cmd and async-shelljs.asyncExec
|
2025-04-30 13:37:02 +02:00 |
|