Henti Smith
|
018a76bb17
|
Merge pull request #9857 from github/henti/new_actions_predicates
Added Workflow.getName and Step.GetId
|
2022-07-19 16:12:54 +01:00 |
|
Henti Smith
|
dcc76ddf36
|
Apply suggestions from code review
Co-authored-by: Henry Mercer <henrymercer@github.com>
|
2022-07-19 15:53:12 +01:00 |
|
Henti Smith
|
0828474192
|
Added Workflow::getName and Step::GetId
|
2022-07-19 15:34:10 +01:00 |
|
Asger F
|
855d4c2ea1
|
Merge pull request #9718 from asgerf/js/case-sensitive-middleware
JS: Add 'case sensitive middleware' query
|
2022-07-14 10:47:58 +02:00 |
|
Erik Krogh Kristensen
|
43a82004b2
|
Merge pull request #9798 from erik-krogh/backtrackers
JS: use small steps in TypeBackTracker correctly
|
2022-07-14 10:28:07 +02:00 |
|
Asger F
|
18c5a8c8da
|
Merge branch 'main' into js/case-sensitive-middleware
|
2022-07-14 09:38:35 +02:00 |
|
Erik Krogh Kristensen
|
fd10947ca0
|
use small steps in TypeBackTracker correctly
|
2022-07-13 10:29:57 +02:00 |
|
Erik Krogh Kristensen
|
a49d34cf0f
|
Merge branch 'main' into missDocParam
|
2022-07-13 09:58:04 +02:00 |
|
Erik Krogh Kristensen
|
7dd095c0d2
|
Merge pull request #9756 from erik-krogh/greyMatter
JS: add model for the gray-matter library to js/code-injection
|
2022-07-01 12:19:12 +02:00 |
|
Erik Krogh Kristensen
|
ef0ec396c4
|
Merge pull request #9754 from erik-krogh/chownr
JS: add model for chownr
|
2022-06-30 22:02:45 +02:00 |
|
Erik Krogh Kristensen
|
11be15aab1
|
inline field into the charpred
|
2022-06-30 09:00:10 +02:00 |
|
Erik Krogh Kristensen
|
f71a64b99d
|
recognize when the js engine in gray-matter is set to something safe
|
2022-06-30 09:00:10 +02:00 |
|
Erik Krogh Kristensen
|
22d285f777
|
add model for the gray-matter libary to js/code-injection
|
2022-06-30 09:00:10 +02:00 |
|
Erik Krogh Kristensen
|
7cef4322e7
|
add model for chownr
|
2022-06-29 22:09:23 +02:00 |
|
Erik Krogh Kristensen
|
0e4954a68c
|
add navigation.navigate as an XSS / URL sink
|
2022-06-29 14:56:20 +02:00 |
|
Erik Krogh Kristensen
|
112caa3f5d
|
rewrite qldoc based on review
|
2022-06-28 13:23:44 +02:00 |
|
Asger F
|
c33690381e
|
JS: Add explicit 'this'
|
2022-06-28 10:21:44 +02:00 |
|
Erik Krogh Kristensen
|
34e7589844
|
sanitize non-strings from unsafe-html-construction
|
2022-06-27 13:53:44 +02:00 |
|
Asger F
|
9e4116618a
|
JS: Add CaseSensitiveMiddlewarePath query
|
2022-06-27 09:08:37 +02:00 |
|
Rasmus Wriedt Larsen
|
3248f7b423
|
Merge pull request #9649 from RasmusWL/certificate-modeling
Python/JS/Ruby: Ignore common words (like certain) as sensitive data source
|
2022-06-23 12:04:58 +02:00 |
|
Rasmus Wriedt Larsen
|
2ce4b7b9fc
|
SensitiveDataHeuristics: sync
|
2022-06-22 11:05:14 +02:00 |
|
Erik Krogh Kristensen
|
e1c34c11ed
|
add all jquery plugin parameters as source to js/html-constructed-from-input
|
2022-06-21 13:22:56 +02:00 |
|
Asger F
|
b46ba896dd
|
Merge pull request #9616 from asgerf/js/without-prop-step-await
JS: Add withoutPropStep and model raw 'await' step with it
|
2022-06-21 09:06:01 +02:00 |
|
Erik Krogh Kristensen
|
79696c6c5f
|
Merge pull request #9572 from erik-krogh/heuristicSteps
JS: add heuristic taint-step for potentially unmodelled libraries
|
2022-06-21 09:00:58 +02:00 |
|
Asger F
|
a0d3a6b5b1
|
JS: Add withoutPropStep and model 'await' steps with it
|
2022-06-20 20:16:07 +02:00 |
|
Asger F
|
5610f654e9
|
JS: Add PackageJson.getTypingsModule
|
2022-06-17 14:40:22 +02:00 |
|
Erik Krogh Kristensen
|
ce323e215b
|
add heuristic taint-step for potentially unmodelled libraries, and meta query for counting potential unmodelled steps
|
2022-06-15 20:27:49 +02:00 |
|
Alex Ford
|
8d195e3188
|
Merge pull request #9157 from alexrford/crypto-op-block-mode
Ruby/Python: Add a `BlockMode` concept for `CryptographicOperations`
|
2022-06-13 21:32:36 +02:00 |
|
Asger F
|
db0ac7b3b3
|
JS: Fix cartesian product in TypeConfusionThroughParameterTampering
|
2022-06-01 11:37:23 +02:00 |
|
Anders Schack-Mulligen
|
9abd2259d3
|
Merge pull request #9381 from aschackmull/redos/perf
ReDoS: Improve performance in ExponentialBackTracking.qll.
|
2022-06-01 10:39:28 +02:00 |
|
Asger F
|
f70f769bb6
|
Merge pull request #9266 from asgerf/js/madman-prep
JS: Some fixes to support proper analysis of d.ts files
|
2022-05-31 15:43:40 +02:00 |
|
CodeQL CI
|
9dd20f113d
|
Merge pull request #8603 from github/max-schaefer/better-amd-modelling
Approved by asgerf, erik-krogh
|
2022-05-31 03:10:32 -07:00 |
|
Anders Schack-Mulligen
|
e36c59b285
|
ReDoS: Sync.
|
2022-05-31 11:04:42 +02:00 |
|
Erik Krogh Kristensen
|
6a6a63e1aa
|
Merge pull request #9354 from erik-krogh/jsStages
JS: collapse a few small stages
|
2022-05-30 20:31:54 +02:00 |
|
Asger F
|
c188aa87c7
|
Merge branch 'main' into js/madman-prep
|
2022-05-30 15:03:14 +02:00 |
|
Rasmus Wriedt Larsen
|
7a6646dcaf
|
Merge pull request #8883 from erik-krogh/pyMaD
Python: add MaD implementation
|
2022-05-30 13:31:07 +02:00 |
|
Asger F
|
5f42866de3
|
Merge pull request #9318 from asgerf/js/type-confusion-parmaeter-tampering-barrier
JS: Fix FP in js/type-confusion-through-parameter-tampering
|
2022-05-30 12:52:37 +02:00 |
|
Erik Krogh Kristensen
|
b700972e6f
|
fix bad join in XmlParers::getAResult
|
2022-05-30 12:37:51 +02:00 |
|
Max Schaefer
|
820dfac48c
|
Manually write out a transitive closure.
|
2022-05-30 12:37:50 +02:00 |
|
Max Schaefer
|
ea70aaff57
|
Improve detection of UMD modules.
We previously required the `define` to appear directly as an expression statement, but there are common patterns where this is not the case.
|
2022-05-30 12:37:50 +02:00 |
|
Erik Krogh Kristensen
|
adb40f9360
|
Merge pull request #9289 from erik-krogh/es2022
JS: Support the remaining of the finished ES2022 proposals
|
2022-05-30 12:27:19 +02:00 |
|
Erik Krogh Kristensen
|
c7a8008897
|
Merge pull request #9235 from kaeluka/extractor-update-typescript-4_7
JS: Update the extractor to use TypeScript 4.7
|
2022-05-30 12:02:06 +02:00 |
|
Asger F
|
cc42f2f824
|
Merge pull request #8606 from asgerf/js/api-graph-api
JS/Python/Ruby: Document how API graphs should be interpreted
|
2022-05-30 10:49:14 +02:00 |
|
Asger F
|
468a4df215
|
Update javascript/ql/lib/semmle/javascript/security/dataflow/TypeConfusionThroughParameterTamperingQuery.qll
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2022-05-27 15:55:25 +02:00 |
|
Erik Krogh Kristensen
|
8c12a7289f
|
collapse a few small stages
|
2022-05-27 13:19:06 +02:00 |
|
Erik Krogh Kristensen
|
d199173923
|
add a getAPrimaryQlClass predicate to ExpressionWithTypeArguments
|
2022-05-25 16:10:13 +00:00 |
|
Asger F
|
5964be4463
|
Merge branch 'main' into js/type-confusion-parmaeter-tampering-barrier
|
2022-05-25 15:53:24 +02:00 |
|
Asger F
|
877a9d8bcc
|
JS: Fix FP in js/type-confusion-through-parameter-tampering
|
2022-05-25 09:53:46 +02:00 |
|
Asger F
|
ced1d21405
|
JS: Add getters for DeclarationSpace members
|
2022-05-24 14:30:36 +02:00 |
|
Asger Feldthaus
|
a5f2c949d3
|
JS: Add UnionOrIntersectionTypeExpr
|
2022-05-24 14:30:36 +02:00 |
|