Asger F
|
bbce52535a
|
JS: Add clarification in another customization doc
|
2022-12-13 15:34:54 +01:00 |
|
Asger F
|
6b15839221
|
JS: Add tests for the examples used in the docs
|
2022-12-13 11:33:12 +01:00 |
|
Asger F
|
ba1364a4cb
|
JS: Add sinks mentioned in doc
Note that 'sql-injection' was already added
|
2022-12-13 11:33:12 +01:00 |
|
Asger F
|
387a673c10
|
Merge pull request #11567 from asgerf/js/data-extensions2
JS: Move MaD models to data extensions
|
2022-12-09 10:09:24 +01:00 |
|
Henry Mercer
|
280bb6864f
|
Merge pull request #11604 from github/codeql-ci/atm/release-0.4.3
JS: Bump version numbers of ML-powered packs after 0.4.3 release
|
2022-12-08 13:04:16 +00:00 |
|
Chris Smowton
|
49bc524fd0
|
Merge remote-tracking branch 'origin/rc/3.8' into smowton/admin/merge-rc38-into-main
|
2022-12-08 11:12:30 +00:00 |
|
Henry Mercer
|
78f15755d7
|
Merge branch 'main' into codeql-ci/atm/release-0.4.3
|
2022-12-07 20:49:26 +00:00 |
|
github-actions[bot]
|
d577eeeea8
|
JS: Bump version of ML-powered library and query packs to 0.4.4
|
2022-12-07 20:05:30 +00:00 |
|
github-actions[bot]
|
9702ea02fb
|
JS: Bump patch version of ML-powered library and query packs
|
2022-12-07 20:01:33 +00:00 |
|
Asger F
|
fcdb2fa03f
|
JS: Remove MaD models from .qll files
|
2022-12-07 11:35:13 +01:00 |
|
Asger F
|
d8e566a50e
|
Add data-extension files
|
2022-12-07 11:35:13 +01:00 |
|
Asger F
|
5af1b367c7
|
Support data extensions
|
2022-12-07 11:35:05 +01:00 |
|
Asger F
|
afe7872838
|
Merge pull request #11565 from asgerf/js/rephined-variable-in-access-path
JS: handle rephined variable in access path
|
2022-12-07 09:26:38 +01:00 |
|
Tiferet Gazit
|
1a9dd48a88
|
Merge pull request #11551 from github/tiferet/endpoint-characteristics-test
ATM: Test for contradictory endpoint characteristics
|
2022-12-06 18:36:41 -08:00 |
|
tiferet
|
cf29cde2e8
|
Apply suggestions from code review
|
2022-12-06 18:05:04 -08:00 |
|
Asger F
|
80777b8c50
|
JS: handle rephined variables in local access paths
|
2022-12-05 15:11:50 +01:00 |
|
Asger F
|
025cfe4064
|
JS: Add reproduction test case
|
2022-12-05 15:11:43 +01:00 |
|
Erik Krogh Kristensen
|
6b9cab23d4
|
Merge pull request #11248 from erik-krogh/js-redosMod
JS: use the shared regex pack
|
2022-12-05 14:48:37 +01:00 |
|
Asger F
|
6bffb11749
|
Merge pull request #11253 from asgerf/merge-package-type-columns
Dynamic: Merge package and type columns
|
2022-12-05 10:57:21 +01:00 |
|
Tiferet Gazit
|
79d8444b94
|
Merge pull request #11532 from github/tiferet/endpoint-filter-test
ATM: Test for endpoints scored at inference time
|
2022-12-02 13:13:52 -08:00 |
|
tiferet
|
93e3c72c6a
|
Test for contradictory endpoint characteristics
|
2022-12-02 10:29:39 -08:00 |
|
tiferet
|
d211decfb4
|
Fix error in last commit
|
2022-12-02 09:03:44 -08:00 |
|
Tiferet Gazit
|
c0aae3d68e
|
Apply suggestions from code review
Co-authored-by: Stephan Brandauer <kaeluka@github.com>
|
2022-12-02 09:00:45 -08:00 |
|
Erik Krogh Kristensen
|
c4cb410970
|
Merge pull request #11472 from erik-krogh/exit-code
JS: make the JS autobuilder consistent with Ruby when no JS code was detected
|
2022-12-02 16:01:02 +01:00 |
|
tiferet
|
d17383d98c
|
Add XssThroughDom
|
2022-12-02 06:59:32 -08:00 |
|
tiferet
|
2e20abca90
|
Undo error from previous commit
Oops, now I see why that wasn't private
|
2022-12-02 06:59:31 -08:00 |
|
tiferet
|
294f34bf07
|
Small improvement
Not strictly needed, but better to keep things private when possible
|
2022-12-02 06:59:31 -08:00 |
|
tiferet
|
a317f2bfe2
|
Test for endpoints scored at inference time
Adds a test to detect changes in the endpoints that get scored at inference time.
|
2022-12-02 06:59:31 -08:00 |
|
Matt Rothenberg
|
95f994a82b
|
Update RequestForgeryBad.js
|
2022-12-02 14:17:37 +01:00 |
|
Matt Rothenberg
|
7d674e7cdc
|
set base URL
|
2022-12-02 14:17:17 +01:00 |
|
Matt Rothenberg
|
c49e9e8503
|
fix: use let for subdomain assignment
|
2022-12-02 14:07:39 +01:00 |
|
Matt Rothenberg
|
a453405365
|
Update RequestForgeryBad.js
|
2022-12-02 14:03:37 +01:00 |
|
Matt Rothenberg
|
2ae0c7e115
|
Update RequestForgeryGood.js
|
2022-12-02 14:02:54 +01:00 |
|
github-actions[bot]
|
5e35785fd0
|
Post-release preparation for codeql-cli-2.11.5
|
2022-12-02 11:37:44 +00:00 |
|
Asger F
|
ef72e222b0
|
Merge pull request #11513 from asgerf/js/api-graph-async-result-node
JS: Remove MkAsyncFunctionResult
|
2022-12-02 11:29:03 +01:00 |
|
Asger F
|
2d578c1a73
|
Merge branch 'main' into merge-package-type-columns
|
2022-12-02 10:00:44 +01:00 |
|
github-actions[bot]
|
31ab22e3a0
|
Release preparation for version 2.11.5
|
2022-12-01 20:05:14 +00:00 |
|
Jean Helie
|
352d1a7e8c
|
ATM: update tests
|
2022-12-01 19:01:30 +01:00 |
|
Jean Helie
|
98923cee94
|
ATM: update missing .qll
|
2022-12-01 18:47:36 +01:00 |
|
Jean Helie
|
ae0d82efd8
|
ATM: update predicate name
|
2022-12-01 18:22:33 +01:00 |
|
Jean Helie
|
880548bafc
|
Merge branch 'main' into tiferet/boost-xss-through-dom
|
2022-12-01 18:13:27 +01:00 |
|
Jean Helie
|
50a3c0d725
|
ATM: update expected ML test values
|
2022-12-01 17:53:09 +01:00 |
|
Jean Helie
|
f388703a3d
|
ATM: update further files following the addition of XssThroughDom query
|
2022-12-01 17:45:07 +01:00 |
|
erik-krogh
|
6289ae329b
|
fix a race-condition
|
2022-12-01 15:27:41 +01:00 |
|
Asger F
|
eb9bee23a0
|
JS: Remove MkAsyncFunctionResult
|
2022-12-01 15:15:27 +01:00 |
|
tiferet
|
4a6de3e444
|
Apply suggestion from code review
|
2022-11-30 17:25:19 -08:00 |
|
tiferet
|
a0a742eb82
|
Rename predicates to fit style guide:
- `getEndpoints` → `appliesToEndpoint`
- `getImplications` → `hasImplications`
- `getAlerts` → `hasAlert`
|
2022-11-30 17:01:56 -08:00 |
|
erik-krogh
|
cddc9db690
|
change back to the old order of extracting externs before Xml
|
2022-11-30 15:46:46 +01:00 |
|
erik-krogh
|
6620ba8cc8
|
Merge branch 'main' into exit-code
|
2022-11-30 15:26:31 +01:00 |
|
tiferet
|
b885249d9d
|
Add a boosted version of XssThroughDOM
|
2022-11-29 17:40:20 -08:00 |
|