Asger F
|
1d793c0a7b
|
JavaScript: fix expected output
|
2018-09-19 14:33:23 +01:00 |
|
semmle-qlci
|
89f2dbf8db
|
Merge pull request #195 from esben-semmle/js/reflected-xss-through-filenames
Approved by asger-semmle
|
2018-09-19 12:42:22 +01:00 |
|
Asger F
|
9384b85bcc
|
JavaScript: ensure prefix sanitizers work for array.join()
|
2018-09-17 14:31:26 +01:00 |
|
Asger F
|
e2cdf5d7ed
|
JavaScript: add string concatenation library
|
2018-09-17 12:47:37 +01:00 |
|
semmle-qlci
|
782e91bb97
|
Merge pull request #167 from bnxi/NodeIntegration
Approved by esben-semmle
|
2018-09-15 21:35:56 +01:00 |
|
Behrang Fouladi Azarnaminy
|
7071c75567
|
revert "Chaning EOL in two files"
This reverts commit ecd08d4560.
|
2018-09-14 09:03:48 -07:00 |
|
Esben Sparre Andreasen
|
444a09a17c
|
JS: add models of five file system libraries
|
2018-09-14 15:30:44 +02:00 |
|
Esben Sparre Andreasen
|
33f98dd1a7
|
JS: add query: js/stored-xss
|
2018-09-14 15:30:44 +02:00 |
|
semmle-qlci
|
abbadf24f0
|
Merge pull request #192 from esben-semmle/js/additional-array-taint-steps
Approved by asger-semmle
|
2018-09-14 10:02:36 +01:00 |
|
semmle-qlci
|
961ecfb43f
|
Merge pull request #187 from esben-semmle/js/additional-whitelisting-form-unbound-event-handlers
Approved by asger-semmle
|
2018-09-14 06:35:39 +01:00 |
|
Esben Sparre Andreasen
|
4c13e6b46b
|
JS: add additional array-specific taint steps
|
2018-09-13 21:36:53 +02:00 |
|
semmle-qlci
|
3d022298dc
|
Merge pull request #186 from Semmle/rc/1.18
Approved by esben-semmle
|
2018-09-13 12:34:54 +01:00 |
|
Esben Sparre Andreasen
|
fcc33ce93d
|
JS: whitelist auto-bind methods in js/unbound-event-handler-receiver
|
2018-09-13 08:41:41 +02:00 |
|
Esben Sparre Andreasen
|
eb10f603ab
|
JS: whitelist decorator-bound methods in js/unbound-event-handler-receiver
|
2018-09-13 08:41:41 +02:00 |
|
Esben Sparre Andreasen
|
1220b50737
|
JS: whitelist _.bindAll-methods in js/unbound-event-handler-receiver
|
2018-09-13 08:41:41 +02:00 |
|
Behrang Fouladi Azarnaminy
|
ecd08d4560
|
Chaning EOL in two files
|
2018-09-12 12:05:57 -07:00 |
|
semmle-qlci
|
9e0ba51280
|
Merge pull request #179 from esben-semmle/js/classify-multi-license-fix
Approved by asger-semmle
|
2018-09-11 21:30:10 +01:00 |
|
Behrang Fouladi Azarnaminy
|
fc087ffb71
|
Replaceing query and test files with suggested ones
|
2018-09-11 12:32:56 -07:00 |
|
semmle-qlci
|
b17aeb689c
|
Merge pull request #118 from esben-semmle/js/request-forgery
Approved by asger-semmle
|
2018-09-11 16:28:59 +01:00 |
|
Esben Sparre Andreasen
|
43c65e02ec
|
JS: classify bundle files based on multiple license comments
|
2018-09-11 15:40:24 +02:00 |
|
Asger F
|
0a4a5da1f0
|
JavaScript: update output of CFG test
|
2018-09-11 12:15:01 +01:00 |
|
Asger F
|
3d444f3dc6
|
JavaScript: fix CFG for EnhancedForStmt
|
2018-09-11 12:15:01 +01:00 |
|
Tom Hvitved
|
70e713122f
|
Merge branch 'rc/1.18' into merge-rc
|
2018-09-11 09:11:03 +02:00 |
|
Behrang Fouladi Azarnaminy
|
02047ea260
|
Edit .expected file
|
2018-09-10 10:27:29 -07:00 |
|
Behrang Fouladi
|
302e271a79
|
Update EnablingNodeIntegration.expected
Change EOL to unix format
|
2018-09-07 09:52:52 -07:00 |
|
Esben Sparre Andreasen
|
3d3b7b0254
|
JS: fix typo in test case
|
2018-09-06 22:54:07 +02:00 |
|
Behrang Fouladi Azarnaminy
|
9179701248
|
JavaScript: Add query for Node.js integration in Electron framework
|
2018-09-06 11:38:08 -07:00 |
|
semmle-qlci
|
62e9946fe2
|
Merge pull request #150 from asger-semmle/ts-asi-bug
Approved by xiemaisi
|
2018-09-05 21:22:29 +01:00 |
|
Aditya Sharad
|
f27945216f
|
Merge rc/1.18 into master.
|
2018-09-05 15:32:30 +01:00 |
|
Esben Sparre Andreasen
|
f63a3b3f39
|
JS: add missing abstract modifier
|
2018-09-05 09:20:45 +02:00 |
|
Esben Sparre Andreasen
|
2306afdebf
|
JS: use extensible architecture for Electron- and NodeClientRequest
|
2018-09-05 09:20:45 +02:00 |
|
Esben Sparre Andreasen
|
0da14fccbd
|
JS: renaming UrlRequests.qll -> ClientRequests.qll
|
2018-09-05 09:20:45 +02:00 |
|
Esben Sparre Andreasen
|
6d78350fee
|
JS: s/URLRequest/ClientRequest, merge with NodeJSLib::ClientRequest
|
2018-09-05 09:20:45 +02:00 |
|
Esben Sparre Andreasen
|
b9d825b379
|
JS: better matching of String.prototype.search in js/regex-injection
|
2018-09-05 08:35:00 +02:00 |
|
Asger F
|
7bd53e72dc
|
TypeScript: fix alerts in ambient code
|
2018-09-04 13:55:48 +01:00 |
|
Asger F
|
003b600e24
|
TypeScript: disable queries that rely on token information
|
2018-09-04 13:18:37 +01:00 |
|
Esben Sparre Andreasen
|
f5a6af54e6
|
JS: add security query: js/request-forgery
|
2018-09-04 09:25:42 +02:00 |
|
Esben Sparre Andreasen
|
2104cf55e3
|
JS: add models of URL requests
|
2018-09-04 09:25:42 +02:00 |
|
Max Schaefer
|
759d98661c
|
Merge pull request #117 from esben-semmle/js/push-sort-taint-steps
JS: support `push` and `sort` taint steps for arrays
|
2018-09-03 09:20:35 +01:00 |
|
Max Schaefer
|
20bff709b1
|
Merge pull request #136 from esben-semmle/js/composed-function-taint
JS: model composed functions (RC)
|
2018-09-03 08:18:20 +01:00 |
|
Max Schaefer
|
7e3adec789
|
Merge pull request #135 from esben-semmle/js/pick-get-taint-steps
JS: model property projection calls (RC)
|
2018-09-03 08:17:42 +01:00 |
|
Max Schaefer
|
69ca103e06
|
Merge pull request #115 from esben-semmle/js/composed-function-taint
JS: model composed functions
|
2018-08-31 08:14:18 +01:00 |
|
Max Schaefer
|
7e18426fde
|
Merge pull request #113 from esben-semmle/js/pick-get-taint-steps
JS: model property projection calls
|
2018-08-31 08:13:40 +01:00 |
|
Esben Sparre Andreasen
|
90b3902244
|
JS: add a taint step for property projection
|
2018-08-30 09:39:02 +02:00 |
|
Esben Sparre Andreasen
|
df97132519
|
JS: add model for property projection
|
2018-08-30 09:39:02 +02:00 |
|
Esben Sparre Andreasen
|
86ab9adb06
|
JS: support push and sort taint steps for arrays
|
2018-08-30 09:14:06 +02:00 |
|
Esben Sparre Andreasen
|
dc72788746
|
JS: add a model of some function composition libraries
|
2018-08-30 08:17:01 +02:00 |
|
semmle-qlci
|
d22a65a66b
|
Merge pull request #108 from esben-semmle/js/classify-generated-data-files
Approved by xiemaisi
|
2018-08-29 14:15:55 +01:00 |
|
Esben Sparre Andreasen
|
02d56306c9
|
JS: classify generated data files
|
2018-08-27 15:06:00 +02:00 |
|
Dave Bartolomeo
|
d920fc7d94
|
Force LF line endings for .ql, .qll, and .qlref files
|
2018-08-24 11:58:58 -07:00 |
|