erik-krogh
|
3355a7a046
|
generalize BarrierGuardFunctionto work on function that have multiple parameters
|
2022-08-16 09:13:15 +02:00 |
|
Asger F
|
eaf3aa7075
|
Merge pull request #10036 from asgerf/js/exports-handling
JS: More precise handling of "exports"
|
2022-08-15 15:32:00 +02:00 |
|
Erik Krogh Kristensen
|
0adb588fe8
|
Merge pull request #9712 from erik-krogh/badRange
JS/RB/PY/Java: add suspicious range query
|
2022-08-15 13:55:44 +02:00 |
|
Asger F
|
3c41f28519
|
JS: Use explicit this
|
2022-08-15 12:49:23 +02:00 |
|
Asger F
|
671573633b
|
JS: Simplify getMain()
|
2022-08-15 12:48:41 +02:00 |
|
Asger F
|
80a37c5863
|
JS: More precise handling of "exports"
|
2022-08-15 11:59:40 +02:00 |
|
erik-krogh
|
3a4a3437b5
|
fix some QL-for-QL warnings
|
2022-08-12 20:38:50 +02:00 |
|
erik-krogh
|
b54f037424
|
Merge branch 'main' into refacReDoS
|
2022-08-12 20:28:30 +02:00 |
|
erik-krogh
|
97681ea219
|
simplify code after review
|
2022-08-12 20:27:50 +02:00 |
|
erik-krogh
|
3403e2f325
|
apply suggestions from code review
|
2022-08-12 20:25:55 +02:00 |
|
erik-krogh
|
4cbfbfe170
|
add call-edge for dynamic dispatch to unknown property from an object literal
|
2022-08-11 12:29:50 +02:00 |
|
Erik Krogh Kristensen
|
887f6557ed
|
fix common misspellings throughout github/codeql
|
2022-08-10 23:21:41 +02:00 |
|
Esben Sparre Andreasen
|
0c6f28014c
|
Merge pull request #9821 from erik-krogh/jsQlFix
JS: fix some QL-for-QL warnings in JS
|
2022-08-09 22:06:29 +02:00 |
|
Erik Krogh Kristensen
|
49276b1f38
|
Merge branch 'main' into refacReDoS
|
2022-08-09 16:18:46 +02:00 |
|
Erik Krogh Kristensen
|
add9e9dac4
|
Merge pull request #9548 from erik-krogh/exports
JS: support the "exports" property in a package.json
|
2022-08-09 12:16:12 +02:00 |
|
Asger F
|
fdcb1fa115
|
Merge pull request #9928 from asgerf/js/source-node-type
JS: Simplify type hierarchy for SourceNode
|
2022-08-08 16:53:20 +02:00 |
|
Evgenii Protsenko
|
50264547bf
|
make array taint-step better
|
2022-08-08 11:00:11 +02:00 |
|
Asger F
|
98a9cb0b55
|
JS: Simplify type hierarchy for SourceNode
The charpred caused spurious type to appear
|
2022-07-29 19:44:10 +02:00 |
|
Henti Smith
|
018a76bb17
|
Merge pull request #9857 from github/henti/new_actions_predicates
Added Workflow.getName and Step.GetId
|
2022-07-19 16:12:54 +01:00 |
|
Henti Smith
|
dcc76ddf36
|
Apply suggestions from code review
Co-authored-by: Henry Mercer <henrymercer@github.com>
|
2022-07-19 15:53:12 +01:00 |
|
Henti Smith
|
0828474192
|
Added Workflow::getName and Step::GetId
|
2022-07-19 15:34:10 +01:00 |
|
Asger F
|
855d4c2ea1
|
Merge pull request #9718 from asgerf/js/case-sensitive-middleware
JS: Add 'case sensitive middleware' query
|
2022-07-14 10:47:58 +02:00 |
|
Erik Krogh Kristensen
|
43a82004b2
|
Merge pull request #9798 from erik-krogh/backtrackers
JS: use small steps in TypeBackTracker correctly
|
2022-07-14 10:28:07 +02:00 |
|
Erik Krogh Kristensen
|
ed80089d7c
|
fix some QL-for-QL warnings in JS
|
2022-07-14 09:45:44 +02:00 |
|
Asger F
|
18c5a8c8da
|
Merge branch 'main' into js/case-sensitive-middleware
|
2022-07-14 09:38:35 +02:00 |
|
Erik Krogh Kristensen
|
595875ff98
|
remove redundant not-equals check
|
2022-07-13 12:06:12 +02:00 |
|
Erik Krogh Kristensen
|
fd10947ca0
|
use small steps in TypeBackTracker correctly
|
2022-07-13 10:29:57 +02:00 |
|
Erik Krogh Kristensen
|
a49d34cf0f
|
Merge branch 'main' into missDocParam
|
2022-07-13 09:58:04 +02:00 |
|
Erik Krogh Kristensen
|
8e52fc97fc
|
changes based on review by Shack
|
2022-07-12 16:02:50 +02:00 |
|
Erik Krogh Kristensen
|
712805f3bf
|
add a!=b to the overlap predicate
|
2022-07-12 16:02:50 +02:00 |
|
Erik Krogh Kristensen
|
592464d98b
|
simplify the overlap computation
|
2022-07-12 16:02:50 +02:00 |
|
Erik Krogh Kristensen
|
aae3e2ddde
|
other changes based on Esbens review
|
2022-07-12 16:02:50 +02:00 |
|
Erik Krogh Kristensen
|
ff25451699
|
rename query to overly-large-range, and rewrite the @description
|
2022-07-12 16:02:46 +02:00 |
|
Erik Krogh Kristensen
|
7dd095c0d2
|
Merge pull request #9756 from erik-krogh/greyMatter
JS: add model for the gray-matter library to js/code-injection
|
2022-07-01 12:19:12 +02:00 |
|
Erik Krogh Kristensen
|
ef0ec396c4
|
Merge pull request #9754 from erik-krogh/chownr
JS: add model for chownr
|
2022-06-30 22:02:45 +02:00 |
|
Erik Krogh Kristensen
|
11be15aab1
|
inline field into the charpred
|
2022-06-30 09:00:10 +02:00 |
|
Erik Krogh Kristensen
|
f71a64b99d
|
recognize when the js engine in gray-matter is set to something safe
|
2022-06-30 09:00:10 +02:00 |
|
Erik Krogh Kristensen
|
22d285f777
|
add model for the gray-matter libary to js/code-injection
|
2022-06-30 09:00:10 +02:00 |
|
Erik Krogh Kristensen
|
7cef4322e7
|
add model for chownr
|
2022-06-29 22:09:23 +02:00 |
|
Erik Krogh Kristensen
|
0e4954a68c
|
add navigation.navigate as an XSS / URL sink
|
2022-06-29 14:56:20 +02:00 |
|
Erik Krogh Kristensen
|
112caa3f5d
|
rewrite qldoc based on review
|
2022-06-28 13:23:44 +02:00 |
|
Asger F
|
c33690381e
|
JS: Add explicit 'this'
|
2022-06-28 10:21:44 +02:00 |
|
Erik Krogh Kristensen
|
a343ceaf8b
|
add suspicious-regexp-range query
|
2022-06-28 09:49:27 +02:00 |
|
Erik Krogh Kristensen
|
34e7589844
|
sanitize non-strings from unsafe-html-construction
|
2022-06-27 13:53:44 +02:00 |
|
Asger F
|
9e4116618a
|
JS: Add CaseSensitiveMiddlewarePath query
|
2022-06-27 09:08:37 +02:00 |
|
Erik Krogh Kristensen
|
28ac47689f
|
changes based on reviews
|
2022-06-24 13:11:46 +02:00 |
|
Erik Krogh Kristensen
|
724721c5c8
|
fix typo
|
2022-06-23 14:36:25 +02:00 |
|
Erik Krogh Kristensen
|
22871138c6
|
simplify the recursion between TTrace and isReachableFromStartTuple
similar to the fix made by Shack in `ExponentialBackTracking.qll`
|
2022-06-23 14:36:25 +02:00 |
|
Erik Krogh Kristensen
|
be37763125
|
improve performance of process() by pruning accept states early
|
2022-06-23 14:36:25 +02:00 |
|
Erik Krogh Kristensen
|
14204be2f9
|
add missing qldoc
|
2022-06-23 14:36:25 +02:00 |
|