Erik Krogh Kristensen
|
6f6c4c4fcc
|
fix tests after change from tabs to spaces
|
2019-11-12 08:48:01 +01:00 |
|
Erik Krogh Kristensen
|
67b38ed301
|
correctly weed out benign calls inside attributes
|
2019-11-11 15:30:33 +01:00 |
|
Felicity Chapman
|
c4f958d396
|
Merge pull request #2263 from sauyon/master
Update links to OWASP cheat sheet
|
2019-11-11 08:51:52 +00:00 |
|
semmle-qlci
|
d9c7549dbe
|
Merge pull request #2279 from max-schaefer/js/touchstone-files
Approved by asger-semmle
|
2019-11-08 14:33:23 +00:00 |
|
Esben Sparre Andreasen
|
9b346b1d52
|
Merge pull request #2260 from max-schaefer/js/_min
JavaScript: Classify files with names ending in `_min` as minified.
|
2019-11-08 13:52:33 +01:00 |
|
semmle-qlci
|
867ed16777
|
Merge pull request #2276 from asger-semmle/inclusion-test
Approved by max-schaefer
|
2019-11-08 10:57:11 +00:00 |
|
Max Schaefer
|
d7831d2680
|
JavaScript: Short-circuit bad-header check on empty files.
|
2019-11-08 10:30:53 +00:00 |
|
Max Schaefer
|
e8510fe71a
|
TypeScript: Skip Touchstone files.
|
2019-11-08 09:17:05 +00:00 |
|
semmle-qlci
|
e65271dfad
|
Merge pull request #2251 from asger-semmle/barrier-guard-improvements
Approved by esbena
|
2019-11-07 15:50:23 +00:00 |
|
semmle-qlci
|
f79c2a7630
|
Merge pull request #2224 from asger-semmle/access-paths-with-source-node-root
Approved by max-schaefer
|
2019-11-07 15:46:14 +00:00 |
|
Asger F
|
8544850945
|
JS: Generalize StringOps::Includes to ::InclusionTest
|
2019-11-07 14:35:17 +00:00 |
|
semmle-qlci
|
3a7f9a588d
|
Merge pull request #2267 from max-schaefer/js/qltest-extractor-options
Approved by asger-semmle
|
2019-11-07 11:36:45 +00:00 |
|
Max Schaefer
|
e314869e5c
|
JavaScript: Classify files with names ending in _min as minified.
We already do the same for `-min` and `.min`. [Here](https://github.com/antoniogarrote/rdfstore-js/blob/master/dist/rdfstore_min.js) is a real-world example.
|
2019-11-07 10:33:47 +00:00 |
|
Sauyon Lee
|
0040c9fb4c
|
Update links to OWASP cheat sheet
|
2019-11-06 20:21:47 -08:00 |
|
Max Schaefer
|
54e40a8977
|
JavaScript: Move --html all extractor options into options file.
|
2019-11-06 16:30:01 +00:00 |
|
Asger F
|
d9beb54dde
|
Merge pull request #2102 from erik-krogh/deferredModel
JS: add Deferred model in js/use-of-returnless-function
|
2019-11-06 14:30:03 +00:00 |
|
semmle-qlci
|
f73caac88d
|
Merge pull request #2254 from asger-semmle/for-of-propread
Approved by max-schaefer
|
2019-11-06 13:44:55 +00:00 |
|
Max Schaefer
|
725059deea
|
JavaScript: Remove --source-type module extractor options.
|
2019-11-06 13:01:59 +00:00 |
|
Max Schaefer
|
3ad5af7cef
|
JavaScript: Move --extract-program-text extractor options into options files.
|
2019-11-06 13:01:55 +00:00 |
|
Max Schaefer
|
6b817203fd
|
JavaScript: Move --tolerate-parse-errors extractor options into options file.
|
2019-11-06 13:01:28 +00:00 |
|
Max Schaefer
|
5681565d4a
|
JavaScript: Move --html elements extractor options into options file.
|
2019-11-06 13:01:28 +00:00 |
|
Max Schaefer
|
8fdf6298b9
|
JavaScript: Remove --platform node extractor options.
|
2019-11-06 13:01:28 +00:00 |
|
Max Schaefer
|
4848372435
|
JavaScript: Replace --externs extractor flag with /** @externs */ comment.
|
2019-11-06 13:01:28 +00:00 |
|
Max Schaefer
|
1fa8c43a8c
|
JavaScript: Remove a redundant extractor option.
|
2019-11-06 13:01:28 +00:00 |
|
Max Schaefer
|
79f1079460
|
JavaScript: Add options files with --experimental extractor options.
|
2019-11-06 13:01:23 +00:00 |
|
Max Schaefer
|
a4bf361f64
|
JavaScript: Remove remaining --experimental extractor options.
|
2019-11-06 12:54:44 +00:00 |
|
Erik Krogh Kristensen
|
19554ff6e7
|
change "e.g." to "for example" in qldoc
|
2019-11-06 13:37:54 +01:00 |
|
Asger F
|
81723ab92a
|
JS: Update GlobalAccessPaths test
|
2019-11-06 11:58:06 +00:00 |
|
Asger F
|
3ec95881b4
|
Update javascript/ql/src/semmle/javascript/GlobalAccessPaths.qll
Co-Authored-By: Max Schaefer <54907921+max-schaefer@users.noreply.github.com>
|
2019-11-06 11:58:06 +00:00 |
|
Asger F
|
7e80823cb6
|
JS: Fix deprecated API usage
|
2019-11-06 11:58:06 +00:00 |
|
Asger F
|
b373901e11
|
JS: Avoid leading dot in access paths
|
2019-11-06 11:58:06 +00:00 |
|
Asger F
|
c365833731
|
JS: Refactor the public access path API
|
2019-11-06 11:58:06 +00:00 |
|
Asger F
|
e90516d4d8
|
JS: Dont use getALocalSource in fromRhs
|
2019-11-06 11:58:06 +00:00 |
|
Asger F
|
bc35f24f31
|
JS: Generalize access paths to arbitrary root nodes
|
2019-11-06 11:58:06 +00:00 |
|
Asger F
|
7a7a8b2b09
|
JS: More steps in getImmediatePredecessor
|
2019-11-06 11:58:06 +00:00 |
|
semmle-qlci
|
04f0c22f24
|
Merge pull request #2203 from erik-krogh/ignorePureFunction
Approved by max-schaefer, mchammer01
|
2019-11-06 09:09:11 +00:00 |
|
Max Schaefer
|
3e92d0ffb5
|
JavaScript: Remove redundant --experimental extractor options.
|
2019-11-05 15:59:24 +00:00 |
|
Erik Krogh Kristensen
|
16b63b3d01
|
move deferred model to the query where it is used
|
2019-11-05 15:45:17 +01:00 |
|
Erik Krogh Kristensen
|
7045cd2648
|
Merge remote-tracking branch 'upstream/master' into deferredModel
|
2019-11-05 15:08:47 +01:00 |
|
semmle-qlci
|
1fe5a9e7e7
|
Merge pull request #2236 from max-schaefer/js/data-flow-exploration
Approved by erik-krogh, esbena
|
2019-11-05 12:15:00 +00:00 |
|
semmle-qlci
|
794d5bda6d
|
Merge pull request #2116 from erik-krogh/arrayCBRet
Approved by max-schaefer
|
2019-11-05 11:32:13 +00:00 |
|
Asger F
|
c373be0dee
|
JS: Update TaintBarriers test
|
2019-11-05 10:26:04 +00:00 |
|
Asger F
|
d8ac0abb7f
|
JS: Add test
|
2019-11-05 10:06:21 +00:00 |
|
Asger F
|
d8f3a2c550
|
JS: Add lvalue of for..of loop as a PropRead
|
2019-11-05 10:01:18 +00:00 |
|
semmle-qlci
|
eb6e8866fa
|
Merge pull request #2247 from max-schaefer/odasa-8149
Approved by asger-semmle, esbena
|
2019-11-05 09:40:54 +00:00 |
|
Erik Krogh Kristensen
|
df3c70e57e
|
add js/ignore-array-result to correctness-core suite
|
2019-11-05 10:40:14 +01:00 |
|
Erik Krogh Kristensen
|
bdb81c268c
|
change tense
|
2019-11-04 18:56:03 +01:00 |
|
Erik Krogh Kristensen
|
8ebfe15f0d
|
apply doc feedback from mchammer01
Co-Authored-By: mc <42146119+mchammer01@users.noreply.github.com>
|
2019-11-04 18:54:43 +01:00 |
|
Erik Krogh Kristensen
|
6cac9619d3
|
add missing not
Co-Authored-By: Max Schaefer <54907921+max-schaefer@users.noreply.github.com>
|
2019-11-04 18:44:13 +01:00 |
|
Max Schaefer
|
016808b92e
|
JavaScript: Address review comments.
|
2019-11-04 17:00:12 +00:00 |
|