erik-krogh
|
2ebce99eae
|
add another example of how to fix the prototype pollution issue
|
2023-05-15 17:24:02 +02:00 |
|
erik-krogh
|
7a338c408e
|
fix typo, the variable in the example is called items
|
2023-05-15 17:23:40 +02:00 |
|
Asger F
|
20e8ee8423
|
Merge pull request #12748 from JarLob/yi
JS: Add more sources, more unit tests, fixes to the GitHub Actions injection query
|
2023-05-15 11:03:00 +02:00 |
|
Max Schaefer
|
5dfe52afd0
|
Merge pull request #13152 from github/max-schaefer/unsafe-shell-command-construction-examples-sync
JavaScript: Use synchronous APIs in examples for js/shell-command-constructed-from-input.
|
2023-05-12 16:50:25 +01:00 |
|
Max Schaefer
|
2e7eb50319
|
JavaScript: Use synchronous APIs in examples for js/shell-command-constructed-from-input.
|
2023-05-12 14:42:11 +01:00 |
|
Max Schaefer
|
a4f6ccf2fc
|
JavaScript: Use gender-neutral language in qhelp for js/user-controlled-bypass
|
2023-05-12 14:21:40 +01:00 |
|
Jaroslav Lobačevski
|
5aa71352dc
|
Update javascript/ql/src/Security/CWE-094/ExpressionInjection.qhelp
Co-authored-by: Asger F <asgerf@github.com>
|
2023-05-09 12:23:52 +02:00 |
|
Kasper Svendsen
|
67950c8e6b
|
JS: Make implicit this receivers explicit
|
2023-05-03 15:31:00 +02:00 |
|
jarlob
|
6e9f54ef55
|
Use double curly braces
|
2023-04-21 19:03:38 +02:00 |
|
smiddy007
|
e4ec1ae261
|
Update InsufficientPasswordHash.qhelp
change file name to original
|
2023-04-17 13:18:47 -04:00 |
|
smiddy007
|
88d2f65c5f
|
Rename InsufficientPasswordHash_NodeJS_fixed.js to InsufficientPasswordHash_fixed.js
|
2023-04-17 13:17:13 -04:00 |
|
smiddy007
|
cbe45f7e55
|
Rename InsufficientPasswordHash_NodeJS.js to InsufficientPasswordHash.js
|
2023-04-17 13:16:57 -04:00 |
|
smiddy007
|
36d7370998
|
Delete InsufficientPasswordHash_CryptoJS_fixed
file not used in qhelp
|
2023-04-17 13:16:25 -04:00 |
|
smiddy007
|
e65daaae49
|
Delete InsufficientPasswordHash_CryptoJS.js
not used in qhelp file
|
2023-04-17 13:15:10 -04:00 |
|
jarlob
|
e9dee3a185
|
Move actions/github-script out of Actions.qll
|
2023-04-14 14:26:23 +02:00 |
|
jarlob
|
3724ea1a7b
|
Extract where parts into predicates
|
2023-04-14 10:49:56 +02:00 |
|
jarlob
|
ac1c20673d
|
Encapsulate github-script
|
2023-04-14 10:23:49 +02:00 |
|
jarlob
|
d80c541da6
|
Encapsulate composite actions
|
2023-04-14 10:06:35 +02:00 |
|
jarlob
|
94065764d5
|
Make predicate name clearer
|
2023-04-14 01:05:21 +02:00 |
|
jarlob
|
79218a3946
|
Use YamlMapping for modeling Env
|
2023-04-14 00:56:51 +02:00 |
|
jarlob
|
dd52ef85cd
|
Rename Env
|
2023-04-13 23:41:31 +02:00 |
|
jarlob
|
7573c615f6
|
Fix warnings
|
2023-04-06 23:07:22 +02:00 |
|
jarlob
|
9c7eecf547
|
Add support for composite actions
|
2023-04-06 22:53:59 +02:00 |
|
jarlob
|
40635e60d1
|
Improve documentation
|
2023-04-05 10:26:02 +02:00 |
|
jarlob
|
9fba7d31f1
|
Improve documentation
|
2023-04-05 10:24:07 +02:00 |
|
jarlob
|
eef1973b93
|
Change UI message
|
2023-04-05 10:05:24 +02:00 |
|
jarlob
|
5c5b9f99a8
|
Add simple taint tracking for env variables
|
2023-04-05 10:03:46 +02:00 |
|
jarlob
|
8ea418216c
|
Look for script injections in actions/github-script
|
2023-04-03 23:13:28 +02:00 |
|
jarlob
|
ba5747dff3
|
fix formatting
|
2023-04-03 15:10:27 +02:00 |
|
jarlob
|
99d634c8a4
|
Add more sources, more unit tests, fixes to the GitHub Actions injection query
|
2023-04-03 15:02:02 +02:00 |
|
Jeroen Ketema
|
17bd9c12d7
|
JS: Fix qhelp after file rename
|
2023-04-03 09:25:19 +02:00 |
|
Asger F
|
dec1e4dfd6
|
Merge pull request #12666 from smiddy007/improve-insufficient-pw-hash-query
JS: Improve insufficient pw hash query
|
2023-03-31 11:58:41 +02:00 |
|
Chris Bellanti
|
6bf94e800b
|
Added check to disabling certificate validation query
|
2023-03-27 12:16:20 -04:00 |
|
smiddy007
|
cef6b95b15
|
Fixed Conflicts due to recent changes to file
|
2023-03-26 22:32:34 -04:00 |
|
smiddy007
|
ad527b8f69
|
Added new example files and renamed existing ones
|
2023-03-26 21:53:22 -04:00 |
|
Alex Ford
|
b000b9b5c0
|
JS: add a missing space in alert message for js/weak-cryptographic-algorithm
|
2023-03-22 11:12:13 +00:00 |
|
Anders Schack-Mulligen
|
8d97fe9ed3
|
JavaScript: Autoformat
|
2023-03-10 09:41:20 +01:00 |
|
erik-krogh
|
393649b7ce
|
don't call environment variables for command-line arguments
|
2023-02-14 14:27:41 +01:00 |
|
erik-krogh
|
36478124ae
|
add process.env and process.argv etc. as source for js/regex-injection
|
2023-02-14 14:21:53 +01:00 |
|
Kristen Newbury
|
231110ddca
|
Update javascript/ql/src/Security/CWE-312/CleartextLogging.qhelp
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2023-02-02 11:12:44 -05:00 |
|
Kristen Newbury
|
dc5eb40d5f
|
Update JS CleartextLogging qhelp
|
2023-02-01 16:29:13 -05:00 |
|
Mark Vogelgesang
|
c9119848d9
|
Updated express-rate-limit example to match implementation examples found on packages README
|
2023-01-18 14:42:40 -05:00 |
|
Tony Torralba
|
3b6dae41cd
|
JavaScript: Remove omittable exists variables
|
2023-01-10 13:37:21 +01:00 |
|
Erik Krogh Kristensen
|
cedc9c0bff
|
Merge pull request #11582 from erik-krogh/heuristics
JS: Add experimental variants of common security queries with more sources
|
2023-01-04 10:46:19 +01:00 |
|
Calum Grant
|
ad55706527
|
Merge branch 'main' into calumgrant/remove-lgtm
|
2023-01-03 10:27:30 +00:00 |
|
Jacques
|
97b8126385
|
Fix javascript
|
2022-12-20 12:45:59 +09:00 |
|
Calum Grant
|
4a37c01c5f
|
JavaScript: Remove references to LGTM
|
2022-12-19 15:15:17 +00:00 |
|
erik-krogh
|
66be8cda06
|
remove more of the implementation into ConditionalBypassQuery.qll
|
2022-12-19 14:37:19 +01:00 |
|
erik-krogh
|
442749bb7f
|
JS: add heuristic variants of queries that use RemoteFlowSource
|
2022-12-19 12:01:22 +01:00 |
|
erik-krogh
|
35e8d6afd4
|
move getACommonTld into a utility module without parameters
|
2022-12-18 17:23:45 +01:00 |
|