amammad
|
5a49f6bb9b
|
fix tests
|
2023-10-06 22:10:57 +02:00 |
|
amammad
|
f5efddc011
|
comments improvement
|
2023-10-06 21:12:59 +02:00 |
|
amammad
|
e45268cd4d
|
improve and fix bugs and add Form Flow Sources test files
|
2023-10-06 21:01:42 +02:00 |
|
amammad
|
eef8137166
|
add Dice package, add global taint steps by SharedTaintStep, use getASuccessor
|
2023-10-06 10:58:26 +02:00 |
|
amammad
|
faaddd4dfe
|
updates for FormParsers and ReadableStream modules, add separate module for Readable Streams, BusBoy RemoteFlowSources is covering more sources now!, modularize
|
2023-10-05 21:46:58 +02:00 |
|
amammad
|
e81a4fc330
|
remove CLI sources Library file and local sources for lower FPs
|
2023-10-01 05:44:13 +10:00 |
|
amammad
|
77dcd68a86
|
v2
|
2023-08-31 21:26:25 +10:00 |
|
amammad
|
d06444e639
|
upgrade additional steps
|
2023-08-30 05:03:19 +10:00 |
|
amammad
|
369bc50709
|
fix comments
|
2023-08-30 04:53:58 +10:00 |
|
amammad
|
516fdf627a
|
update stream pipe
|
2023-06-28 00:09:39 +10:00 |
|
amammad
|
c7a7594821
|
merge all ql files into one
|
2023-06-27 01:56:23 +10:00 |
|
amammad
|
8a80a734d8
|
fix an accident :)
|
2023-06-26 20:20:00 +10:00 |
|
amammad
|
3bd45a8536
|
fix query identifier
|
2023-06-26 03:01:19 +10:00 |
|
amammad
|
effb8024a4
|
fix yargs bug
|
2023-06-25 23:30:24 +10:00 |
|
amammad
|
c16a2827d7
|
fix format warnings/errors
|
2023-06-25 23:24:12 +10:00 |
|
amammad
|
307187f6c1
|
V1
|
2023-06-23 06:06:37 +10:00 |
|
Jami
|
5259a6ecfc
|
Merge pull request #13324 from jcogs33/jcogs33/shared-sink-kind-validation
Shared: share MaD kind validation across languages
|
2023-06-20 11:56:12 -04:00 |
|
Tony Torralba
|
8f6d2ed2f9
|
Adjust ZipSlip query description according to review suggestions.
|
2023-06-19 10:27:41 +02:00 |
|
Tony Torralba
|
3c4d938cf1
|
Apply code review suggestions.
Co-authored-by: Asger F <asgerf@github.com>
|
2023-06-19 10:20:19 +02:00 |
|
Tony Torralba
|
433fc680ec
|
Apply suggestions from code review
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
|
2023-06-19 10:17:40 +02:00 |
|
Tony Torralba
|
c97868f774
|
Add change notes
|
2023-06-16 09:01:02 +02:00 |
|
Tony Torralba
|
3e96fe60c5
|
Go/Java/JS/Python/Ruby: Update the description and qhelp of the ZipSlip query
All filesystem operations, not just writes, with paths built from untrusted archive entry names are dangerous
|
2023-06-16 08:52:44 +02:00 |
|
Asger F
|
318a60b208
|
Merge pull request #13456 from asgerf/js/vuex-perf
JS: Restrict length of state path in vuex model
|
2023-06-14 19:50:06 +02:00 |
|
Asger F
|
22b98c8959
|
JS: Restrict length of state path in vuex model
|
2023-06-14 15:48:58 +02:00 |
|
Jami
|
35591113c2
|
Merge branch 'main' into jcogs33/shared-sink-kind-validation
|
2023-06-14 08:06:34 -04:00 |
|
Asger F
|
f737054216
|
Merge pull request #13380 from asgerf/js/fix-sink-kind
JS: Fix invalid source kind in test
|
2023-06-14 12:56:58 +02:00 |
|
Asger F
|
5aea6fc16c
|
JS: Remove dataExtensions clause from test qlpack
|
2023-06-14 10:42:31 +02:00 |
|
Asger F
|
21831516f4
|
JS: use test-local data extensions
|
2023-06-14 10:38:33 +02:00 |
|
erik-krogh
|
3fd9f26b52
|
use consistent indentation in mongoose.js
|
2023-06-12 16:40:42 +02:00 |
|
erik-krogh
|
cd6f738f72
|
add mongoose.Types.ObjectId.isValid as a sanitizer-guard for NoSQL injection
|
2023-06-12 16:38:11 +02:00 |
|
Jami Cogswell
|
9abe3e3da4
|
Shared: use a module as input to 'KindValidation'
|
2023-06-09 14:35:37 -04:00 |
|
Jami Cogswell
|
da58b2afc8
|
Shared: move shared file to 'shared' folder and add parameterized module for 'getInvalidModelKind'
|
2023-06-08 20:05:27 -04:00 |
|
Asger F
|
76a8e9827e
|
Merge pull request #13283 from asgerf/js/restrict-regex-search-function
JS: Be more conservative about flagging "search" call arguments as regex
|
2023-06-08 10:50:51 +02:00 |
|
Erik Krogh Kristensen
|
6ba7f9a238
|
Merge pull request #13352 from erik-krogh/once-again-deps-not-py-cpp
delete old deprecations
|
2023-06-07 13:00:57 +02:00 |
|
Asger F
|
17f9239c33
|
JS: Fix invalid source kind in test
|
2023-06-06 13:40:06 +02:00 |
|
Erik Krogh Kristensen
|
0e6693bdea
|
Merge pull request #12874 from erik-krogh/ts51
JS: Add support for TS 5.1
|
2023-06-06 11:51:51 +02:00 |
|
Erik Krogh Kristensen
|
b78cd48954
|
Merge pull request #13329 from erik-krogh/sqlhelp
JS: improve the sql-injection help page
|
2023-06-06 08:44:44 +02:00 |
|
Jami Cogswell
|
5a23421d9a
|
Shared: minor updates to comments
|
2023-06-05 13:46:56 -04:00 |
|
erik-krogh
|
3cb2ec4e87
|
fix nits from doc review
|
2023-06-05 19:06:07 +02:00 |
|
Jami Cogswell
|
9d5972acc2
|
Shared: update qldocs
|
2023-06-05 12:18:34 -04:00 |
|
Jami Cogswell
|
3f1dc8e5c7
|
Shared: add outdated Swift sink kinds
|
2023-06-05 12:18:34 -04:00 |
|
Jami Cogswell
|
62ac0dc471
|
Shared: add outdated sink kind msg to 'getInvalidModelKind' for all languages
|
2023-06-05 12:18:33 -04:00 |
|
Jami Cogswell
|
76f5dca861
|
Shared: move 'OutdatedSinkKind' to shared file and add outdated JS and C# sink kinds
|
2023-06-05 12:18:33 -04:00 |
|
Jami Cogswell
|
7b629f5d63
|
Shared: include 'qltest%' and 'test-%'
|
2023-06-05 12:18:33 -04:00 |
|
Jami Cogswell
|
254e447923
|
JS/Python/Ruby: update getInvalidModelKind
|
2023-06-05 12:18:33 -04:00 |
|
Jami Cogswell
|
7317c29eea
|
Shared: update kind information
|
2023-06-05 12:18:33 -04:00 |
|
Jami Cogswell
|
0ab1848b70
|
JS/Python/Ruby: use 'SharedModelValidation' file
|
2023-06-05 12:18:33 -04:00 |
|
Jami Cogswell
|
ddb5d92ef8
|
Shared: add source, summary, and neutral shared valid kinds
|
2023-06-05 12:18:33 -04:00 |
|
Jami Cogswell
|
869f820fcf
|
Shared: add 'SharedModelValidation' file as experiment
|
2023-06-05 12:18:33 -04:00 |
|
Jami Cogswell
|
e24e3a6115
|
JS/Python/Ruby: add getInvalidModelKind as experiment
|
2023-06-05 12:18:33 -04:00 |
|