Erik Krogh Kristensen
|
e6884cf705
|
Merge pull request #18959 from erik-krogh/faster-routing
JS: ensure the result from getPathFromFork is unique (to avoid a blowup)
|
2025-03-10 21:45:14 +01:00 |
|
Erik Krogh Kristensen
|
b945466b9f
|
Merge pull request #18892 from asgerf/js/membership-regexp-test
JS: Sharpen up EnumerationRegExp
|
2025-03-10 16:21:54 +01:00 |
|
Asger F
|
08c9f6fa1e
|
Merge pull request #18798 from erik-krogh/ts58
JS: upgrade TypeScript to 5.8
|
2025-03-10 14:48:03 +01:00 |
|
Asger F
|
d84368eb54
|
Merge pull request #18858 from Napalys/js/react-relay
JS: React-relay support
|
2025-03-10 14:33:23 +01:00 |
|
erik-krogh
|
b70643b1a1
|
ensure the result from getPathFromFork is unique (to avoid a blowup)
|
2025-03-10 12:53:51 +01:00 |
|
Napalys
|
d077d6807a
|
Applied changes from comments
Co-authored-by: Asgerf <asgerf@github.com>
|
2025-03-10 12:24:45 +01:00 |
|
Erik Krogh Kristensen
|
8eb69079b7
|
fix typo from copy-pasted change-note
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
|
2025-03-10 09:41:48 +01:00 |
|
erik-krogh
|
b641caa508
|
update TypeScript version to 5.8.1-RC
|
2025-03-10 09:20:29 +01:00 |
|
Napalys
|
c12c12c416
|
Added modeling for react-relay functions that retrieve data.
|
2025-03-06 18:30:21 +01:00 |
|
Napalys
|
0166e76cca
|
Add change note
|
2025-03-06 18:10:24 +01:00 |
|
Napalys
|
1443f314a1
|
Added react-relay useFragment as threat model source.
|
2025-03-06 18:10:23 +01:00 |
|
Anders Schack-Mulligen
|
c6761db2fc
|
SSA: Replace the Guards interface in the SSA data flow integration.
|
2025-03-05 13:29:31 +01:00 |
|
Asger F
|
c3ad805fe8
|
JS: Sharpen up EnumerationRegExp
|
2025-02-28 13:58:11 +01:00 |
|
Asger F
|
baa7e35589
|
Merge pull request #18834 from Napalys/js/tanstack
JS: Support 'response' threat model and @tanstack/react-query
|
2025-02-25 16:16:06 +01:00 |
|
Napalys
|
3360829a58
|
Updated change note with response threat model info.
Co-authored-by: Asgerf <asgerf@github.com>
|
2025-02-25 15:22:14 +01:00 |
|
Napalys
|
bf77ffef37
|
Applied comment
Co-authored-by: Asgerf <asgerf@github.com>
|
2025-02-25 13:57:39 +01:00 |
|
Napalys
|
e2927b2fad
|
Updated tanstack to use API graph.
|
2025-02-25 11:48:44 +01:00 |
|
Anders Schack-Mulligen
|
57c4fd6f25
|
JS: Combine phi reads and ssa input nodes into SynthReadNode class.
|
2025-02-25 09:23:53 +01:00 |
|
Anders Schack-Mulligen
|
1af753cd0c
|
JS: Use shared barrier guard for falsy check.
|
2025-02-24 13:00:06 +01:00 |
|
Anders Schack-Mulligen
|
09b2aeb53a
|
SSA: Replace use-use step implementation in data-flow integration.
|
2025-02-24 10:58:14 +01:00 |
|
Anders Schack-Mulligen
|
4e515bc2f5
|
JS: Remove reference to isInputInto
|
2025-02-21 14:48:24 +01:00 |
|
Napalys
|
3587ba593a
|
Add change note and added tanstack to supported framework list
|
2025-02-21 13:47:48 +01:00 |
|
Napalys
|
ab0241c1de
|
Added missing doc strings for Tanstack queries
|
2025-02-21 13:32:49 +01:00 |
|
Napalys
|
1227a7eedc
|
Add Tanstack framework support and enhance data flow tracking for fetch responses
|
2025-02-21 13:24:00 +01:00 |
|
Asger F
|
a1b7096125
|
Merge pull request #18783 from asgerf/js/downward-calls
JS: Resolve calls downward in class hierarchy
|
2025-02-20 09:01:58 +01:00 |
|
Asger F
|
58c8b5fa2b
|
Merge pull request #18790 from asgerf/js/no-implicit-array-taint
JS: Do not taint whole array when storing into ArrayElement
|
2025-02-19 13:23:31 +01:00 |
|
Asger F
|
e1c280500e
|
Merge pull request #18749 from Kwstubbs/express
JS: Add result.download to Express as Path Traversal Sink
|
2025-02-19 09:08:36 +01:00 |
|
Asger F
|
804a1a6cb0
|
JS: Handle array of sorting criteria
|
2025-02-18 16:58:04 +01:00 |
|
Asger F
|
7486742c37
|
JS: Fix model of _.sortBy
|
2025-02-18 16:53:40 +01:00 |
|
Asger F
|
ad4522c781
|
JS: Make 'typeStrongerThan' transitive
|
2025-02-18 16:04:48 +01:00 |
|
Asger F
|
e40ee821c2
|
JS: Update a qldoc comment
|
2025-02-18 16:02:47 +01:00 |
|
Asger F
|
e610683377
|
JS: Linter fix
|
2025-02-18 09:25:23 +01:00 |
|
github-actions[bot]
|
ad24f94a77
|
Post-release preparation for codeql-cli-2.20.5
|
2025-02-17 17:58:24 +00:00 |
|
github-actions[bot]
|
6f4562f3bd
|
Release preparation for version 2.20.5
|
2025-02-17 16:55:54 +00:00 |
|
Asger F
|
a54f0a74f1
|
JS: Target post-update node instead of getALocalSource
getAPropertyWrite() contains getALocalSource() under the the hood. Don't rely on that to find the successor of a mutation.
|
2025-02-17 15:00:02 +01:00 |
|
Asger F
|
6e074c301f
|
JS: Port lodash callback steps to flow summaries
Not all of lodash, just the callbacks we already modeled plus a few easy ones
|
2025-02-17 14:54:45 +01:00 |
|
Erik Krogh Kristensen
|
7fa41c438f
|
Merge pull request #18794 from erik-krogh/v-flag
JS: Add support for the regex V flag
|
2025-02-17 13:56:48 +01:00 |
|
Asger F
|
4e325d9f1c
|
JS: Convert some exception steps to legacy
|
2025-02-17 11:53:50 +01:00 |
|
Asger F
|
352924fb8c
|
JS: Handle a few other stringification contexts
|
2025-02-17 11:36:28 +01:00 |
|
Asger F
|
33ab7db98a
|
JS: Handle Array.prototype.toString calls
|
2025-02-17 11:25:03 +01:00 |
|
Asger F
|
d87534c7d0
|
JS: Model Array#toString
|
2025-02-17 11:13:36 +01:00 |
|
Asger F
|
0ca9b2285b
|
Merge pull request #18740 from asgerf/js/more-precise-diff-informed
JS: Provide more precise related locations
|
2025-02-17 10:27:15 +01:00 |
|
erik-krogh
|
6ebffd59f6
|
add change-note
|
2025-02-16 19:23:44 +01:00 |
|
Napalys
|
3ec038e7b6
|
JS: Added predicate to check if v flag is used on regular expression
|
2025-02-16 18:31:08 +01:00 |
|
Asger F
|
283954d515
|
JS: Do not store into arrays implicitly
|
2025-02-14 16:06:43 +01:00 |
|
Asger F
|
ab5fc9f4d7
|
JS: Implement viableImplInCallContext
|
2025-02-14 13:25:19 +01:00 |
|
Asger F
|
ff7bc7c25e
|
JS: Track types of classes in data flow
|
2025-02-14 12:44:45 +01:00 |
|
Asger F
|
b8b2b9a470
|
JS: Resolve calls downward in the class hierarchy
|
2025-02-14 11:17:19 +01:00 |
|
Asger F
|
7df3e647d1
|
JS: Use US spelling
|
2025-02-14 10:28:55 +01:00 |
|
Asger F
|
26dcbf7a2a
|
JS: Migrate URLSearchParams model to flow summaries
|
2025-02-13 11:51:33 +01:00 |
|