semmle-qlci
|
091c6c063c
|
Merge pull request #2856 from esbena/js/fix-RegExp-getPredecessor-getSuccessor
Approved by max-schaefer
|
2020-02-20 09:50:52 +00:00 |
|
Asger Feldthaus
|
479770dc07
|
JS: Recognize class members in more cases
|
2020-02-19 17:04:41 +00:00 |
|
Max Schaefer
|
4346691cdc
|
JavaScript: Distinguish {lo} and {lo,} in the regular expression parser.
|
2020-02-19 08:26:14 +00:00 |
|
Erik Krogh Kristensen
|
e359e1a373
|
use a barrier directly instead of a barrier guard
|
2020-02-18 10:57:28 +01:00 |
|
Esben Sparre Andreasen
|
8a9587fc91
|
JS: fix RegExp::getSuccessor/getPredecessor for sequence end/starts
|
2020-02-17 13:40:53 +01:00 |
|
Esben Sparre Andreasen
|
c5ee436b16
|
JS: add RegExp::getSuccessor/getPredecessor tests
|
2020-02-17 13:06:55 +01:00 |
|
semmle-qlci
|
23ed2bcc64
|
Merge pull request #2782 from asger-semmle/js/export-as-ns
Approved by erik-krogh, max-schaefer
|
2020-02-17 11:22:58 +00:00 |
|
Max Schaefer
|
f181111886
|
JavaScript: Add model of http2 compatibility API.
Also deprecated the `httpOrHttps` predicate, which was now only used in one place and seemed a little pointless anyway.
|
2020-02-14 11:14:31 +00:00 |
|
Asger Feldthaus
|
ad10414604
|
JS: Update expected output of existing test
|
2020-02-07 16:57:57 +00:00 |
|
Erik Krogh Kristensen
|
06e13cb3a1
|
Merge branch 'master' of git.semmle.com:Semmle/ql into FalsySanitizer
|
2020-02-07 16:13:02 +01:00 |
|
Erik Krogh Kristensen
|
1ece6b9afe
|
update expected output of tests
|
2020-02-07 12:57:51 +01:00 |
|
Asger Feldthaus
|
a2fa6bb41f
|
JS: Add test case for lazy-cache
|
2020-02-07 09:50:37 +00:00 |
|
Erik Krogh Kristensen
|
2865723059
|
add test for new barrier
|
2020-02-06 15:44:33 +01:00 |
|
Asger Feldthaus
|
7090124a1d
|
JS: Implement type inference through export * as ns
|
2020-02-06 14:29:35 +00:00 |
|
Asger Feldthaus
|
2b77c7969d
|
JS: Add tests for 'export * as ns'
|
2020-02-06 14:04:12 +00:00 |
|
Asger Feldthaus
|
f5c805bad1
|
JS: Move tests into one file
|
2020-02-06 13:55:29 +00:00 |
|
Asger Feldthaus
|
54c521d41c
|
JS: Fix typo in test query
|
2020-02-06 13:50:06 +00:00 |
|
semmle-qlci
|
5125dc7939
|
Merge pull request #2730 from esbena/js/model-path-parse
Approved by asgerf
|
2020-02-05 21:35:55 +00:00 |
|
semmle-qlci
|
52f34d7178
|
Merge pull request #2715 from erik-krogh/PrivateFields
Approved by asgerf
|
2020-02-05 10:20:28 +00:00 |
|
Esben Sparre Andreasen
|
f6ad22dd1f
|
Merge pull request #2758 from asger-semmle/js/string-concat-concat
JS: Model concat() calls as string concatenation
|
2020-02-05 10:41:02 +01:00 |
|
Erik Krogh Kristensen
|
e525cf0959
|
generalize isAdditionalLoadStoreStep such that it loads and stores different properties
|
2020-02-05 09:40:16 +01:00 |
|
Asger Feldthaus
|
b4df03767d
|
JS: Ignore obvious Array.prototype.concat calls
|
2020-02-04 16:36:41 +00:00 |
|
semmle-qlci
|
4b89eee683
|
Merge pull request #2757 from max-schaefer/js/resolveMainModule-extensions
Approved by asgerf
|
2020-02-04 13:07:08 +00:00 |
|
Asger Feldthaus
|
bf2c944b4f
|
JS: Model concat() calls as string concatenation
|
2020-02-04 10:20:37 +00:00 |
|
Max Schaefer
|
e21c24c60e
|
JavaScript: Add failing test case.
|
2020-02-04 09:39:04 +00:00 |
|
semmle-qlci
|
bd51ef35b7
|
Merge pull request #2731 from erik-krogh/CVE527
Approved by esbena
|
2020-02-04 08:38:26 +00:00 |
|
Erik Krogh Kristensen
|
e3189aaa47
|
raise syntax error on declaration of private method, and add syntax tests for private fields
|
2020-02-03 16:00:25 +01:00 |
|
Asger Feldthaus
|
9abf5f06e6
|
TS: Resolve imports using TypeScript symbols
|
2020-02-03 09:32:56 +00:00 |
|
semmle-qlci
|
d995d5a4a0
|
Merge pull request #2716 from esbena/js/additional-koa-requests
Approved by erik-krogh
|
2020-01-31 18:30:42 +00:00 |
|
Erik Krogh Kristensen
|
279c584bb8
|
fix FP in js/path-injection by recognizing more prefix checks
|
2020-01-31 11:03:11 +01:00 |
|
semmle-qlci
|
f8d0b4e602
|
Merge pull request #2618 from erik-krogh/ExceptionalPromise
Approved by asgerf
|
2020-01-31 07:59:09 +00:00 |
|
Esben Sparre Andreasen
|
5f1317fa2d
|
JS: model path.parse and its ponyfill package: "path-parse"
|
2020-01-30 21:26:18 +01:00 |
|
semmle-qlci
|
3158b8401a
|
Merge pull request #2705 from erik-krogh/CVE75
Approved by asgerf
|
2020-01-30 13:07:05 +00:00 |
|
Esben Sparre Andreasen
|
a6d3afd817
|
JS: support additional Koa request sources
|
2020-01-29 14:49:01 +01:00 |
|
Esben Sparre Andreasen
|
d4d910b681
|
JS: add koa test
|
2020-01-29 14:41:23 +01:00 |
|
Erik Krogh Kristensen
|
b8834ffcad
|
add support for private fields in classes
|
2020-01-29 13:10:45 +01:00 |
|
Erik Krogh Kristensen
|
cb16116b4d
|
adjust type-tracking on custom EventEmitters
|
2020-01-28 14:00:26 +01:00 |
|
Asger Feldthaus
|
b306571d52
|
JS: Type-track react component factories
|
2020-01-28 10:22:04 +00:00 |
|
Erik Krogh Kristensen
|
b526a2ea0f
|
implement a model of WebSocket and ws based on the EventEmitter model
|
2020-01-22 14:46:53 +01:00 |
|
semmle-qlci
|
007b0795ec
|
Merge pull request #2636 from erik-krogh/NewSocketIO
Approved by esbena
|
2020-01-22 13:46:11 +00:00 |
|
Erik Krogh Kristensen
|
5063e3820d
|
update expected output
|
2020-01-22 11:18:47 +01:00 |
|
Erik Krogh Kristensen
|
8370699344
|
add support for creating a promise with another resolved promise, e.g: Promise.resolve(otherPromise)
|
2020-01-21 20:11:27 +01:00 |
|
Erik Krogh Kristensen
|
fe0b6a86d7
|
add data-flow steps for when Promise handlers return other promises
|
2020-01-21 16:15:18 +01:00 |
|
Erik Krogh Kristensen
|
d8b25ef5a2
|
add data-flow steps for resolved promises using pseudo-properties
|
2020-01-21 15:52:50 +01:00 |
|
Erik Krogh Kristensen
|
6648e2751f
|
remove use of .getAlocalSource() i custom load/store test
|
2020-01-21 15:49:42 +01:00 |
|
Erik Krogh Kristensen
|
569ee8fc8d
|
add support for subclasses of EventEmitter
|
2020-01-21 12:08:50 +01:00 |
|
Erik Krogh Kristensen
|
026092559c
|
changes based on review
|
2020-01-20 15:53:58 +01:00 |
|
Erik Krogh Kristensen
|
ad813ef86c
|
add flowsTo to the use of isAdditionalLoadStep
|
2020-01-20 14:16:29 +01:00 |
|
Erik Krogh Kristensen
|
ffbd0f6632
|
update expected test output
|
2020-01-20 09:56:40 +01:00 |
|
Erik Krogh Kristensen
|
b3b132c66d
|
Merge remote-tracking branch 'upstream/master' into ExceptionalPromise
|
2020-01-20 09:20:09 +01:00 |
|