Asger F
|
9dcb61e771
|
JS: Remove js/actions/actions-artifact-leak
Superseded by actions/secrets-in-artifacts
|
2025-06-23 14:39:28 +02:00 |
|
erik-krogh
|
37a1727043
|
fix example in clear-text-logging qhelp to actually be bad
|
2025-01-27 11:31:28 +01:00 |
|
Asger F
|
d52bc971b8
|
Merge branch 'main' into js/shared-dataflow-merge-main
|
2024-11-20 14:05:03 +01:00 |
|
Mikaël Barbero
|
881fe0ba57
|
fix: add "actions" tag to ActionsArtifactLeak
Similar to javascript/ql/src/Security/CWE-094/ExpressionInjection.ql
|
2024-11-05 15:58:46 +01:00 |
|
Asger F
|
1cd00a118c
|
Merge branch 'main' into js/shared-dataflow-merge-main
|
2024-09-18 14:57:50 +02:00 |
|
Alvaro Muñoz
|
5d1da861a2
|
fix: Use YamlScalar for booleans
|
2024-09-06 23:21:41 +02:00 |
|
Alvaro Muñoz
|
5df3af2272
|
Fix alert message
|
2024-09-06 23:06:57 +02:00 |
|
Alvaro Muñoz
|
d9e8792d33
|
[javascript] Query to detect GITHUB_TOKEN leaked in artifacts
|
2024-09-06 22:55:58 +02:00 |
|
Asger F
|
2296a273c4
|
JS: Port BuildArtifactLeak
|
2023-10-13 13:15:04 +02:00 |
|
Asger F
|
40d68cb4dc
|
JS: Port CleartextStorage
|
2023-10-13 13:15:04 +02:00 |
|
Asger F
|
b8a6f81669
|
JS: Port CleartextLogging
|
2023-10-13 13:15:04 +02:00 |
|
Kristen Newbury
|
231110ddca
|
Update javascript/ql/src/Security/CWE-312/CleartextLogging.qhelp
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2023-02-02 11:12:44 -05:00 |
|
Kristen Newbury
|
dc5eb40d5f
|
Update JS CleartextLogging qhelp
|
2023-02-01 16:29:13 -05:00 |
|
erik-krogh
|
368f84785b
|
fix some more style-guide violations in the alert-messages
|
2022-10-07 11:22:22 +02:00 |
|
erik-krogh
|
24f2e3cc07
|
update alert-messages of the sensitive data queries to match #10314
|
2022-09-06 12:25:36 +02:00 |
|
erik-krogh
|
aa56ca37ae
|
make the alert messages of taint-tracking queries more consistent
|
2022-09-05 14:04:52 +02:00 |
|
Rasmus Wriedt Larsen
|
c05ffd4d00
|
JS/PY: Remove CWE-315 form CleartextLogging
Since it is not relevant for this query:
CWE-315: Cleartext Storage of Sensitive Information in a Cookie
See https://cwe.mitre.org/data/definitions/315.html
|
2021-11-24 14:59:18 +01:00 |
|
Erik Krogh Kristensen
|
55434653f5
|
add CWE-532 to the clear-text-logging query
|
2021-11-10 14:15:49 +01:00 |
|
Asger Feldthaus
|
f6da030572
|
JS: Migrate to *Query.qll convention
|
2021-08-12 09:30:18 +02:00 |
|
Calum Grant
|
771e686946
|
Update security-severity scores
|
2021-06-15 13:25:17 +01:00 |
|
Calum Grant
|
a594afb828
|
Add security-severity metadata
|
2021-06-10 20:11:08 +01:00 |
|
Erik Krogh Kristensen
|
69888f90c6
|
add dot after bullet-point
|
2020-06-17 17:15:39 +02:00 |
|
Erik Krogh Kristensen
|
315faaffee
|
small corrections in documentation
Co-authored-by: Asger F <asgerf@github.com>
|
2020-06-15 23:40:27 +02:00 |
|
Erik Krogh Kristensen
|
d2716c532c
|
qhelp
|
2020-06-15 14:59:48 +02:00 |
|
Erik Krogh Kristensen
|
eb00da5b31
|
improve readability
Co-authored-by: Asger F <asgerf@github.com>
|
2020-06-09 20:02:46 +02:00 |
|
Erik Krogh Kristensen
|
be71ddf7bb
|
introduce basic BuildArtifactLeak query
|
2020-06-09 15:27:55 +02:00 |
|
Max Schaefer
|
aebc5bc6c3
|
JavaScript: Update qhelp example for CleartextStorage.
|
2019-02-08 08:43:22 +00:00 |
|
Max Schaefer
|
31bb39a810
|
JavaScript: Autoformat all QL files.
|
2019-01-07 10:15:45 +00:00 |
|
Max Schaefer
|
3fcd02ab0e
|
JavaScript: Rename hasPathFlow to hasFlowPath for consistency with other languages.
|
2018-11-14 11:23:17 +00:00 |
|
Max Schaefer
|
52ae757279
|
JavaScript: Select Nodes (instead of PathNodes) everywhere.
|
2018-11-14 09:16:40 +00:00 |
|
Max Schaefer
|
e365b722ee
|
JavaScript: Select source and sink in all path queries.
|
2018-11-14 09:16:40 +00:00 |
|
Max Schaefer
|
11d6259dbf
|
JavaScript: Move from Node to PathNode.
|
2018-11-14 09:16:40 +00:00 |
|
Max Schaefer
|
8d87f556e1
|
JavaScript: Add import DataFlow::PathGraph.
|
2018-11-14 09:16:40 +00:00 |
|
Max Schaefer
|
60a1357092
|
JavaScript: Make all taint-based security queries have @kind path-problem.
|
2018-11-14 09:16:40 +00:00 |
|
Max Schaefer
|
65bcf0f526
|
JavaScript: Refactor security queries for uniformity.
|
2018-11-14 09:16:40 +00:00 |
|
Esben Sparre Andreasen
|
2b9f5c3fa2
|
JS: remove check for test-environment in js/clear-text-logging
|
2018-08-21 22:32:52 +02:00 |
|
Esben Sparre Andreasen
|
6950bfe915
|
JS: review fixups in documentation and comments
|
2018-08-21 22:32:52 +02:00 |
|
Esben Sparre Andreasen
|
0c4fb15651
|
JS: add query js/cleartext-logging
|
2018-08-20 08:34:16 +02:00 |
|
Pavel Avgustinov
|
b55526aa58
|
QL code and tests for C#/C++/JavaScript.
|
2018-08-02 17:53:23 +01:00 |
|