Asger F
|
52c729b161
|
JS: Use underlying types in DataFlow::Node
|
2025-04-23 14:27:02 +02:00 |
|
Asger F
|
21f4349cc6
|
Create TypeResolution.qll
|
2025-04-23 14:27:01 +02:00 |
|
Asger F
|
a374b04f0f
|
Create UnderlyingTypes.qll
|
2025-04-23 14:27:00 +02:00 |
|
Asger F
|
45ed331115
|
Create NameResolution.qll
|
2025-04-23 14:26:59 +02:00 |
|
Asger F
|
7586631934
|
JS: Add test
|
2025-04-23 14:26:57 +02:00 |
|
Asger F
|
f8be64b313
|
JS: Add helper for getting local type names
|
2025-04-23 14:26:55 +02:00 |
|
Asger F
|
0f981b4a1e
|
JS: Avoid accidental recursion with API graphs
|
2025-04-23 14:26:54 +02:00 |
|
Asger F
|
bcf26ef537
|
JS: Make Closure concepts based on AST instead
|
2025-04-23 14:26:52 +02:00 |
|
Asger F
|
372606a93d
|
JS: Do not ignore variables from ambient declarations
|
2025-04-23 14:26:51 +02:00 |
|
Asger F
|
f18335da5b
|
JS: Add ImportSpecifier.getImportDeclaration()
|
2025-04-23 14:26:50 +02:00 |
|
Asger F
|
4443dec443
|
JS: Exclude externs from CallGraph meta-query
|
2025-04-23 14:26:48 +02:00 |
|
Asger F
|
6d58293478
|
Disable noisy meta query
|
2025-04-23 14:26:47 +02:00 |
|
Asger F
|
ae55f2c80f
|
Add meta query
|
2025-04-23 14:26:45 +02:00 |
|
Asger F
|
c2cab184ac
|
Merge pull request #19283 from asgerf/js/rest-pattern-fix
JS: Fix missing flow into rest pattern lvalue
|
2025-04-22 10:37:36 +02:00 |
|
github-actions[bot]
|
d78736b1bf
|
Post-release preparation for codeql-cli-2.21.1
|
2025-04-15 16:33:15 +00:00 |
|
github-actions[bot]
|
b961c5961d
|
Release preparation for version 2.21.1
|
2025-04-14 09:53:06 +00:00 |
|
Napalys Klicius
|
86313715a4
|
Merge pull request #19184 from Napalys/js/request_handlers
JS: Support for `Request` and `NextRequest`
|
2025-04-14 08:07:24 +02:00 |
|
Asger F
|
6c01709048
|
JS: Update more test output
|
2025-04-11 15:15:22 +02:00 |
|
Napalys Klicius
|
3d7c0201d9
|
Merge pull request #19231 from Napalys/js/typed_array
JS: Taint propagation from low-level `ArrayBuffer` to `Strings`
|
2025-04-11 11:29:01 +02:00 |
|
Napalys
|
11abbf8c4a
|
Now nextUrl is of type parameter and loosen the restriction for NextAppRouteHandler
|
2025-04-11 11:19:12 +02:00 |
|
Napalys Klicius
|
92e4f112c0
|
Update javascript/ql/lib/semmle/javascript/frameworks/Next.qll
Co-authored-by: Asger F <asgerf@github.com>
|
2025-04-11 11:08:40 +02:00 |
|
Napalys Klicius
|
d0dcf897cb
|
Update javascript/ql/lib/semmle/javascript/internal/flow_summaries/Strings.qll
Co-authored-by: Asger F <asgerf@github.com>
|
2025-04-11 11:04:08 +02:00 |
|
Napalys Klicius
|
d17d29a387
|
Merge pull request #19218 from Napalys/js/upgrade_websocket
JS: Refactor `WebSocket` to use `API` graphs
|
2025-04-11 10:05:54 +02:00 |
|
Napalys
|
e3f1720f9c
|
RenamedDecodeLike to Decode and updated propagatesFlow
|
2025-04-11 10:04:09 +02:00 |
|
Napalys
|
2c4b3527b4
|
Added change note
|
2025-04-11 09:42:12 +02:00 |
|
Napalys
|
678eccb417
|
Added searchParams.get as potential source for SSRF
|
2025-04-11 09:42:07 +02:00 |
|
Napalys
|
8674b61e5a
|
Added SSRF test case with searchParams for NextRequest
|
2025-04-11 09:26:16 +02:00 |
|
Napalys
|
6e09a65da0
|
Added support for NextRequest middleware SSRF.
|
2025-04-11 08:43:36 +02:00 |
|
Napalys
|
734ad2d767
|
Removed legacy Consistency check as it is redundant now with inline test expectations.
|
2025-04-11 08:43:08 +02:00 |
|
Napalys
|
208487f236
|
Added middleware test
|
2025-04-11 08:39:47 +02:00 |
|
Asger F
|
719456e27d
|
JS: Fix missing flow into rest pattern lvalue
|
2025-04-11 08:37:09 +02:00 |
|
Asger F
|
7703b1fab5
|
JS: Add test for missing getALocalSource flow for rest pattern
|
2025-04-11 08:37:07 +02:00 |
|
Napalys Klicius
|
43bf0beae9
|
Merge pull request #19263 from Napalys/js/make-dir-lib
JS: Add support for `make-dir` package
|
2025-04-10 15:09:43 +02:00 |
|
Napalys
|
86b64afa13
|
Added NextResponse to the ResponseCall class it models similar near idential behaviour.
|
2025-04-10 15:06:44 +02:00 |
|
Napalys
|
8acb0243ad
|
Added test cases for NextResponse and Response
|
2025-04-10 14:57:40 +02:00 |
|
Napalys
|
63a3953b0c
|
Enhance Next.js API endpoint handling for compatibility with both Pages and App Router structures.
|
2025-04-10 14:48:17 +02:00 |
|
Napalys
|
81cba7fa2f
|
Added test cases with missing alerts for Request and NextRequest.
|
2025-04-10 14:43:48 +02:00 |
|
Asger F
|
eac14b9837
|
Merge pull request #19200 from asgerf/js/web-response
JS: Add sinks for calls to 'new Response()'
|
2025-04-10 14:41:32 +02:00 |
|
Napalys
|
171a84609e
|
Applied copilot suggestion.
|
2025-04-10 14:13:48 +02:00 |
|
Asger F
|
3da1f261f7
|
JS: Change note
|
2025-04-10 07:21:48 +02:00 |
|
Asger F
|
cfa1a9b603
|
JS: Update extractor version string
|
2025-04-10 07:20:53 +02:00 |
|
Asger F
|
1434f7acd2
|
JS: Tolerate trailing comma in JSON array
Previously we'd fail to extract some tsconfig.json files because of this.
|
2025-04-10 07:20:51 +02:00 |
|
Asger F
|
800dd168c2
|
JS: Add failing TRAP test for trailing comma
|
2025-04-10 07:20:49 +02:00 |
|
Napalys
|
5243f90c90
|
Brought back old methods and marked them as deprecated
|
2025-04-09 14:56:24 +02:00 |
|
Napalys
|
5ec71ab9af
|
Added change note
|
2025-04-09 14:42:34 +02:00 |
|
Napalys
|
ce2fc25cdb
|
Added make-dir model as data
|
2025-04-09 14:42:29 +02:00 |
|
Napalys
|
674f40b35f
|
Added test cases for make-dir package.
|
2025-04-09 14:41:12 +02:00 |
|
Napalys Klicius
|
2dca95af92
|
Update javascript/ql/lib/change-notes/2025-04-07-websocket.md
Co-authored-by: Asger F <asgerf@github.com>
|
2025-04-09 14:26:00 +02:00 |
|
Napalys
|
0c52b5ad95
|
Added summary flow for StringFromCharCode
|
2025-04-09 14:24:43 +02:00 |
|
Napalys Klicius
|
f02783a9c6
|
Merge pull request #19210 from Napalys/js/mkdirp
JS: Modeling of `mkdirp` functions
|
2025-04-09 13:43:37 +02:00 |
|