Asger Feldthaus
|
3804d3fcfd
|
JS: Remove Import->SourceNode dependency from lazy cache
|
2020-04-02 23:03:20 +01:00 |
|
Asger Feldthaus
|
8f930fc3e6
|
JS: Remove recursive SourceNode from AngularJS
|
2020-04-02 12:25:33 +01:00 |
|
Asger Feldthaus
|
ee106b1103
|
JS: Remove tautological SourceNode::Range subclasses
|
2020-04-02 12:21:17 +01:00 |
|
semmle-qlci
|
0feb7f87e4
|
Merge pull request #2761 from erik-krogh/UrlSearch
Approved by asgerf
|
2020-03-31 09:46:48 +01:00 |
|
semmle-qlci
|
73dd4c8686
|
Merge pull request #3133 from asger-semmle/js/dictionary-taint-step-regression
Approved by esbena
|
2020-03-31 09:28:55 +01:00 |
|
semmle-qlci
|
fce04f0bd0
|
Merge pull request #3127 from erik-krogh/PromiseTrack
Approved by asgerf
|
2020-03-30 11:56:33 +01:00 |
|
Asger Feldthaus
|
a317b87b81
|
JS: Fix perf issue in DictionaryTaintStep
|
2020-03-30 11:23:47 +01:00 |
|
Erik Krogh Kristensen
|
4864e77430
|
Merge branch 'master' of git.semmle.com:Semmle/ql into UrlSearch
|
2020-03-27 15:59:29 +01:00 |
|
semmle-qlci
|
fad902fc9b
|
Merge pull request #3095 from erik-krogh/MorePerf
Approved by asgerf
|
2020-03-27 12:51:37 +00:00 |
|
semmle-qlci
|
9b3400337b
|
Merge pull request #3130 from erik-krogh/PreciseSteps
Approved by asgerf
|
2020-03-27 12:18:28 +00:00 |
|
semmle-qlci
|
1975a83cdd
|
Merge pull request #3116 from max-schaefer/js/postgres-type-tracking
Approved by asgerf
|
2020-03-27 09:23:52 +00:00 |
|
Erik Krogh Kristensen
|
d3e1a258fa
|
autoformat
|
2020-03-27 09:34:56 +01:00 |
|
Erik Krogh Kristensen
|
be11418c77
|
autoformat
|
2020-03-27 00:18:41 +01:00 |
|
Erik Krogh Kristensen
|
6b507c6933
|
add urlSuffix support to DomBasedXSS
|
2020-03-26 15:47:59 +01:00 |
|
Erik Krogh Kristensen
|
baf50c832c
|
more precise charpreds in taint steps
|
2020-03-26 15:30:43 +01:00 |
|
Erik Krogh Kristensen
|
8f45c8fe83
|
use LoadStoreStep for type-tracking promises
|
2020-03-25 23:54:57 +01:00 |
|
Erik Krogh Kristensen
|
1a2983fe39
|
support small steps for promise tracking
|
2020-03-25 23:54:57 +01:00 |
|
Erik Krogh Kristensen
|
9a78d38df0
|
add a new LoadStoreStep as a StepSummary for TypeTracking
|
2020-03-25 23:54:56 +01:00 |
|
semmle-qlci
|
e7fd97e72b
|
Merge pull request #3119 from erik-krogh/SockJS
Approved by esbena
|
2020-03-25 21:36:29 +00:00 |
|
Erik Krogh Kristensen
|
4b0bc6b2b3
|
autoformat
|
2020-03-25 19:47:41 +01:00 |
|
semmle-qlci
|
cf5b1f0cd5
|
Merge pull request #3019 from erik-krogh/ArrayStep
Approved by asgerf
|
2020-03-25 12:08:44 +00:00 |
|
Erik Krogh Kristensen
|
abcdfe3c53
|
use LibraryName class for websocket library names
|
2020-03-25 13:06:21 +01:00 |
|
Erik Krogh Kristensen
|
f2b9e2019c
|
remove isRelevant from flowStep
|
2020-03-25 09:46:07 +01:00 |
|
Erik Krogh Kristensen
|
6f0e507242
|
outline predicate to fix join-ordering
|
2020-03-25 09:44:03 +01:00 |
|
Erik Krogh Kristensen
|
3000486b35
|
add more isRelevant calls
|
2020-03-25 09:42:24 +01:00 |
|
Erik Krogh Kristensen
|
1d8e103322
|
autoformat
|
2020-03-25 00:19:23 +01:00 |
|
Max Schaefer
|
efbcec09ef
|
JavaScript: Add type tracking to Postgres model.
|
2020-03-24 17:30:07 +00:00 |
|
Erik Krogh Kristensen
|
36981f385a
|
Merge branch 'master' of git.semmle.com:Semmle/ql into MorePathSinks
|
2020-03-24 11:20:33 +01:00 |
|
semmle-qlci
|
4c9a6b73ee
|
Merge pull request #3107 from erik-krogh/FArgs
Approved by esbena
|
2020-03-24 08:32:56 +00:00 |
|
Erik Krogh Kristensen
|
fa710c5864
|
Merge remote-tracking branch 'upstream/master' into UrlSearch
|
2020-03-24 00:23:15 +01:00 |
|
Erik Krogh Kristensen
|
6a1491d83d
|
add SockJS to the existing WebSocket model
|
2020-03-23 23:56:11 +01:00 |
|
semmle-qlci
|
e5590091a0
|
Merge pull request #3109 from max-schaefer/js/performance-fixes
Approved by asgerf
|
2020-03-23 16:08:07 +00:00 |
|
Max Schaefer
|
55e7b22cdf
|
JavaScript: Autoformat.
|
2020-03-23 14:37:04 +00:00 |
|
Erik Krogh Kristensen
|
7bc7ffffd6
|
autoformat
|
2020-03-23 14:10:07 +01:00 |
|
Max Schaefer
|
b13e6141a2
|
JavaScript: Inline promiseStep/4.
|
2020-03-23 12:01:52 +00:00 |
|
Asger F
|
6c2842bd49
|
Merge pull request #2919 from asger-semmle/js/property-barriers
JS: Make sanitizers no longer block taint inside an object
|
2020-03-23 11:43:18 +00:00 |
|
Erik Krogh Kristensen
|
2c43d1d731
|
fix FP in superfluous-trailing-arguments related to Function.arguments
|
2020-03-23 10:40:35 +01:00 |
|
Erik Krogh Kristensen
|
f88cc2a977
|
inline promiseStep predicate
|
2020-03-20 09:07:52 +01:00 |
|
Erik Krogh Kristensen
|
90a324148d
|
add extra sinks to js/tainted-path
|
2020-03-20 09:07:39 +01:00 |
|
semmle-qlci
|
deb20fc37f
|
Merge pull request #3076 from esbena/js/even-more-mongoose-improvements
Approved by erik-krogh
|
2020-03-19 12:03:53 +00:00 |
|
Max Schaefer
|
ee62706ad2
|
JavaScript: Split up a predicate to avoid bad join order.
|
2020-03-19 11:47:53 +00:00 |
|
Max Schaefer
|
d91e6a4893
|
JavaScript: Avoid a few bad join orders.
|
2020-03-19 11:47:53 +00:00 |
|
Asger Feldthaus
|
4f42675b35
|
JS: Autformat
|
2020-03-19 09:36:27 +00:00 |
|
Asger Feldthaus
|
3ae33e3c1a
|
JS: Update prototype pollution query
|
2020-03-18 23:59:25 +00:00 |
|
Asger Feldthaus
|
b6ca4fbee3
|
JS: Add getDefaultSourceLabel()
|
2020-03-18 23:52:25 +00:00 |
|
Asger Feldthaus
|
7393844699
|
JS: Update some queries that used data as source
|
2020-03-18 11:55:13 +00:00 |
|
Asger Feldthaus
|
18eea96cf8
|
JS: Autoformat
|
2020-03-18 11:55:13 +00:00 |
|
Asger Feldthaus
|
4e75fe3977
|
JS: Update some qldoc comments
|
2020-03-18 11:55:13 +00:00 |
|
Asger Feldthaus
|
83606e7b60
|
JS: Dont use data label in taint-tracking configs
|
2020-03-18 11:55:12 +00:00 |
|
Esben Sparre Andreasen
|
b1a722fcda
|
JS: typo fix
|
2020-03-18 10:11:38 +01:00 |
|