aegilops
|
c003f265b0
|
Fixed missing li closing tag
|
2024-07-08 10:58:06 +01:00 |
|
aegilops
|
fc6fba8d06
|
Fixed CWE tags
|
2024-07-01 14:25:47 +01:00 |
|
aegilops
|
d1d082982a
|
More external references
|
2024-07-01 14:25:29 +01:00 |
|
aegilops
|
f22778960b
|
Fixed expected test results for Helmet query
|
2024-06-26 11:31:57 +01:00 |
|
aegilops
|
1ecd72727d
|
Renamed README to CUSTOMIZING, removed details from qhelp and referenced md doc instead
|
2024-06-19 17:59:43 +01:00 |
|
aegilops
|
a07639f4f6
|
Set severity to 7.0, in line with other configuration queries
|
2024-06-19 17:43:41 +01:00 |
|
aegilops
|
26f1b36736
|
Fixed formatting
|
2024-06-19 17:41:58 +01:00 |
|
aegilops
|
252c9e9416
|
Added data extension to set defaults, updated help, added README to explain customization
|
2024-06-19 17:27:17 +01:00 |
|
Paul Hodgkinson
|
3a98edb60b
|
Merge branch 'main' into aegilops/js/insecure-helmet-middleware
|
2024-06-19 12:53:32 +01:00 |
|
aegilops
|
d142f830da
|
Change note and changed name of query in .ql file
|
2024-06-19 12:04:32 +01:00 |
|
aegilops
|
8a3cec4977
|
Fix formatting for check
|
2024-06-19 11:38:20 +01:00 |
|
Paolo Tranquilli
|
b7a2ea8981
|
CI: accept other diagnostic format related test changes
|
2024-06-19 11:33:50 +02:00 |
|
aegilops
|
de96d3951d
|
Renamed to helmetProperty everywhere
|
2024-06-19 10:15:06 +01:00 |
|
aegilops
|
f4691b1919
|
Changed to more-modern Dataflow libraries
|
2024-06-19 10:11:06 +01:00 |
|
aegilops
|
81ef255a87
|
Change to helmetProperty from helmetSetting variable name
|
2024-06-19 10:09:50 +01:00 |
|
aegilops
|
da9e1e61a4
|
Moved examples into separate files
|
2024-06-18 19:50:06 +01:00 |
|
github-actions[bot]
|
8a25081a0e
|
Post-release preparation for codeql-cli-2.17.5
|
2024-06-10 15:33:08 +00:00 |
|
github-actions[bot]
|
877bfa2468
|
Release preparation for version 2.17.5
|
2024-06-10 13:40:39 +00:00 |
|
aegilops
|
7ee5655f31
|
Merge branch 'aegilops/js/insecure-helmet-middleware' of https://github.com/aegilops/codeql into aegilops/js/insecure-helmet-middleware
|
2024-06-07 15:50:15 +01:00 |
|
aegilops
|
975811ae59
|
Change layout of qhelp example code
|
2024-06-07 15:50:06 +01:00 |
|
Paul Hodgkinson
|
43a140e62c
|
Merge branch 'main' into aegilops/js/insecure-helmet-middleware
|
2024-06-07 15:46:18 +01:00 |
|
aegilops
|
7136763c37
|
Formatting
|
2024-06-07 15:36:39 +01:00 |
|
aegilops
|
465d64a810
|
Removed br tags
|
2024-06-07 15:34:45 +01:00 |
|
aegilops
|
29322f5ff0
|
Merge branch 'aegilops/js/insecure-helmet-middleware' of https://github.com/aegilops/codeql into aegilops/js/insecure-helmet-middleware
|
2024-06-07 15:32:23 +01:00 |
|
aegilops
|
f5d465f08a
|
Added data extension to allow setting extra required Helmet features
|
2024-06-07 15:32:11 +01:00 |
|
Anders Schack-Mulligen
|
0c47203580
|
Javascript: Add support for pretty-printed provenace in tests.
|
2024-06-07 11:47:49 +02:00 |
|
Asger F
|
6e0f3df573
|
Merge pull request #14120 from asgerf/dynamic/typemodel-istypeused
Dynamic: add TypeModel.isTypeUsed
|
2024-06-06 15:31:16 +02:00 |
|
Paolo Tranquilli
|
096a31dbef
|
Mark all integration tests as legacy
This is in preparation for the new integration test framework. Tests
marked thus will be run by the current framework and ignored by the new
one.
|
2024-05-31 16:04:50 +02:00 |
|
github-actions[bot]
|
906b65d09c
|
Post-release preparation for codeql-cli-2.17.4
|
2024-05-28 18:02:25 +00:00 |
|
github-actions[bot]
|
33b4ae8bbb
|
Release preparation for version 2.17.4
|
2024-05-28 15:44:32 +00:00 |
|
Erik Krogh Kristensen
|
c743abad54
|
Merge pull request #14294 from am0o0/amammad-js-CodeInjection_execa
JS: provide command execution sinks for execa package
|
2024-05-24 09:20:19 +02:00 |
|
Dave Bartolomeo
|
613ccaac1d
|
Add change note to all v1.0.0 packs
|
2024-05-23 13:01:22 -04:00 |
|
erik-krogh
|
c80f48b23a
|
Merge branch 'main' into amammad-js-CodeInjection_execa
|
2024-05-23 08:02:22 +02:00 |
|
Dave Bartolomeo
|
ffe4c8c87b
|
Update all pack versions to 1.0.0
|
2024-05-22 13:39:08 -04:00 |
|
erik-krogh
|
a30bac14e9
|
add change-note
|
2024-05-21 22:14:39 +02:00 |
|
Paul Hodgkinson
|
65dfd4c860
|
Merge branch 'main' into aegilops/js/insecure-helmet-middleware
|
2024-05-21 14:46:49 +01:00 |
|
aegilops
|
68e21a594a
|
Fixed query help formatting issues
|
2024-05-21 14:35:18 +01:00 |
|
aegilops
|
bda794fde7
|
Fixed wrong filenames in the InsecureHelmet tests
|
2024-05-21 14:34:58 +01:00 |
|
aegilops
|
83037b1195
|
Adjust structure to avoid warnings about message
|
2024-05-21 13:51:13 +01:00 |
|
Asger F
|
3b211089d6
|
JS: Remove redundant import
|
2024-05-21 14:40:17 +02:00 |
|
Asger F
|
6f19fc2fcd
|
JS: Add isTypeUsed to avoid overpruning
|
2024-05-21 14:38:52 +02:00 |
|
Asger F
|
632cce2c16
|
JS: Add failing test due to overpruning
|
2024-05-21 14:20:13 +02:00 |
|
Asger F
|
43abc72780
|
JS: Add TypeModel.isTypeUsed
f
|
2024-05-21 14:19:56 +02:00 |
|
Joe Farebrother
|
01a6c5e82f
|
Merge pull request #16446 from joefarebrother/shared-sensitive-heuristics
Ruby/Python/JS/Swift: Add category of Private information to shared sensitive data heuristics
|
2024-05-21 09:07:13 +01:00 |
|
erik-krogh
|
c166cb406a
|
Merge branch 'main' into amammad-js-CodeInjection_execa
|
2024-05-21 08:48:12 +02:00 |
|
aegilops
|
8300aeb0a0
|
Tests for InsecureHelmet
|
2024-05-20 12:05:42 +01:00 |
|
aegilops
|
3a885eaf9f
|
Insecure Helmet middle configuration - frameguard or CSP to 'false'
|
2024-05-20 11:58:55 +01:00 |
|
Erik Krogh Kristensen
|
03cf9b702c
|
Merge pull request #14291 from am0o0/amammad-js-CodeInjection_Shelljs
JS: Shelljs improvement
|
2024-05-17 11:14:11 +02:00 |
|
am0o0
|
42a9962519
|
make shellJSMember predicate private, improve predicate document
|
2024-05-16 14:05:06 +02:00 |
|
Asger F
|
499c4df79b
|
Merge pull request #13554 from am0o0/amammad-js-bombs
JS: Decompression Bombs
|
2024-05-16 13:25:41 +02:00 |
|