Erik Krogh Kristensen
|
a17d152ca4
|
Merge branch 'js-team-sprint' into priv-file-polish
|
2020-06-19 13:19:10 +02:00 |
|
Erik Krogh Kristensen
|
7d6dac479c
|
Merge branch 'js-team-sprint' into https-fix
|
2020-06-18 16:53:01 +02:00 |
|
Erik Krogh Kristensen
|
dcf617b235
|
Merge branch 'js-team-sprint' into bad-random-polish
|
2020-06-18 16:52:32 +02:00 |
|
Erik Krogh Kristensen
|
1556b62007
|
Merge branch 'js-team-sprint' into priv-file-polish
|
2020-06-18 16:40:53 +02:00 |
|
Esben Sparre Andreasen
|
3f67e90374
|
JS: rename query, support timeouts, add documentation, add to suite
|
2020-06-18 13:01:02 +02:00 |
|
Esben Sparre Andreasen
|
d9d8eb4805
|
JS: avoid type inference in the taint steps (just a nice to have)
|
2020-06-18 13:00:45 +02:00 |
|
Esben Sparre Andreasen
|
7b97fd07a8
|
JS: add query js/memory-exhaustion
|
2020-06-18 13:00:45 +02:00 |
|
Erik Krogh Kristensen
|
7a1c161e9e
|
Merge branch 'js-team-sprint' into https-fix
|
2020-06-17 21:04:44 +02:00 |
|
Erik Krogh Kristensen
|
218338b4f1
|
Merge branch 'js-team-sprint' into bad-random-polish
|
2020-06-17 21:04:00 +02:00 |
|
Erik Krogh Kristensen
|
73f26956a6
|
Merge branch 'js-team-sprint' into priv-file-polish
|
2020-06-17 21:03:09 +02:00 |
|
Erik Krogh Kristensen
|
bdda587247
|
Merge branch 'js-team-sprint' into build-leaks
|
2020-06-17 19:51:30 +02:00 |
|
Erik Krogh Kristensen
|
cd111fe350
|
Merge pull request #3721 from asger-semmle/js/non-linear-pattern-msg
JS: Improve alert message in js/non-linear-pattern
|
2020-06-17 13:10:56 +02:00 |
|
Erik Krogh Kristensen
|
fa0a8c3423
|
add documentation examples as tests
|
2020-06-17 11:37:32 +02:00 |
|
Erik Krogh Kristensen
|
639907967f
|
add home/rootdir as leaking folders
|
2020-06-17 10:46:42 +02:00 |
|
Erik Krogh Kristensen
|
6675ddae12
|
add more libraries that serve static files to js/exposure-of-private-files
|
2020-06-17 10:00:59 +02:00 |
|
Erik Krogh Kristensen
|
210e71cd93
|
update expected output
|
2020-06-16 21:52:59 +02:00 |
|
Erik Krogh Kristensen
|
5ce17bea60
|
add qhelp for js/bad-code-sanitization
|
2020-06-16 16:23:41 +02:00 |
|
Erik Krogh Kristensen
|
a0951f76b6
|
add additional taint steps when type-tracking RemoteFlowSource
|
2020-06-16 14:55:07 +02:00 |
|
semmle-qlci
|
07bff646d8
|
Merge pull request #3641 from asger-semmle/js/pre-call-graph-steps
Approved by erik-krogh
|
2020-06-16 13:41:55 +01:00 |
|
Erik Krogh Kristensen
|
696879653a
|
add qhelp to js/biased-cryptographic-random
|
2020-06-16 11:10:09 +02:00 |
|
Asger Feldthaus
|
3242f5ed94
|
JS: Include qhelp example in test suite
|
2020-06-15 17:37:26 +01:00 |
|
Asger Feldthaus
|
7091a9f704
|
JS: Special-case alert message for type annotations
|
2020-06-15 17:17:47 +01:00 |
|
Asger Feldthaus
|
c8ab69af11
|
JS: Avoid duplicate alerts
|
2020-06-15 16:57:54 +01:00 |
|
Asger Feldthaus
|
f380898126
|
JS: Add test showing duplicate alerts
|
2020-06-15 16:40:37 +01:00 |
|
Asger Feldthaus
|
51d143d6f1
|
JS: Add test with destructuring pattern that looks like type annotations
|
2020-06-15 16:35:36 +01:00 |
|
Erik Krogh Kristensen
|
3ef5dc74a1
|
add backtracking to find division that end up being rounded
|
2020-06-15 17:10:10 +02:00 |
|
semmle-qlci
|
3728e1afd3
|
Merge pull request #3715 from asger-semmle/js/returned-functions
Approved by erik-krogh, esbena
|
2020-06-15 15:32:54 +01:00 |
|
Asger Feldthaus
|
17010e25a1
|
JS: Update another test
|
2020-06-15 13:55:46 +01:00 |
|
semmle-qlci
|
57c8dd85a4
|
Merge pull request #2801 from esbena/js/bulky-route-handler-registration
Approved by asgerf
|
2020-06-15 13:06:22 +01:00 |
|
Asger Feldthaus
|
c4179eb81d
|
JS: Update test
|
2020-06-15 11:13:20 +01:00 |
|
semmle-qlci
|
b6b838774e
|
Merge pull request #3704 from asger-semmle/js/cve-serve
Approved by esbena
|
2020-06-15 09:54:17 +01:00 |
|
Asger Feldthaus
|
315f3389d1
|
JS: Autoformat test
|
2020-06-12 19:58:05 +01:00 |
|
Asger F
|
d844e0025a
|
Merge pull request #3651 from esbena/js/bad-multicharacter-sanitization
JS: initial version of IncompleteMultiCharacterSanitization.ql
|
2020-06-12 16:25:22 +01:00 |
|
Asger Feldthaus
|
5548606f21
|
JS: Add test
|
2020-06-12 13:02:33 +01:00 |
|
Erik Krogh Kristensen
|
01c51eea89
|
Merge pull request #3680 from erik-krogh/bad-code-sanitizer
JS: Add query to detect bad code sanitizers
|
2020-06-12 14:00:21 +02:00 |
|
semmle-qlci
|
2342d3dba3
|
Merge pull request #3662 from asger-semmle/js/package-export-fixes
Approved by esbena
|
2020-06-12 12:18:23 +01:00 |
|
Erik Krogh Kristensen
|
c9fc1a378d
|
Merge pull request #3663 from erik-krogh/bad-crypto
JS: Introduce query to detect biased random number generators
|
2020-06-12 11:32:12 +02:00 |
|
Asger Feldthaus
|
4c536dde20
|
JS: Propagate locally returned functions out of calls
|
2020-06-12 10:07:37 +01:00 |
|
Erik Krogh Kristensen
|
908edb39b9
|
unsecure -> insecure
|
2020-06-12 11:02:26 +02:00 |
|
Erik Krogh Kristensen
|
86b23b239e
|
Merge pull request #3656 from erik-krogh/destruct-yargs
JS: support rest-patterns inside property patterns
|
2020-06-12 10:57:24 +02:00 |
|
Asger Feldthaus
|
6531db3cca
|
JS: Add test
|
2020-06-12 09:56:38 +01:00 |
|
Erik Krogh Kristensen
|
9780fcf8fe
|
fix ftp protocol regexp
|
2020-06-12 10:54:56 +02:00 |
|
Erik Krogh Kristensen
|
3f957103ed
|
improve alert message - and autoformat
|
2020-06-12 10:53:19 +02:00 |
|
Erik Krogh Kristensen
|
02c4a0477d
|
add tests for js/build-artifact-leak
|
2020-06-12 10:21:37 +02:00 |
|
Esben Sparre Andreasen
|
1bdae109c5
|
Merge pull request #3686 from esbena/js/insecure-http-options
JS: add query js/disabling-certificate-validation
|
2020-06-12 08:40:12 +02:00 |
|
semmle-qlci
|
5c2f1169d0
|
Merge pull request #3679 from asger-semmle/js/dom-value-ref-restriction
Approved by erik-krogh, esbena
|
2020-06-12 07:39:26 +01:00 |
|
Esben Sparre Andreasen
|
243e3ad9e3
|
Merge pull request #3672 from esbena/js/server-crashing-route-handler
JS: add initial version of ServerCrash.ql
|
2020-06-12 08:38:37 +02:00 |
|
Erik Krogh Kristensen
|
5b491313ad
|
add simple query for detecting sensitive files downloaded over unsecure connection
|
2020-06-11 23:19:28 +02:00 |
|
Erik Krogh Kristensen
|
ef72c03ca9
|
use simpler taint-step for DestructingPattern
|
2020-06-11 23:16:46 +02:00 |
|
Esben Sparre Andreasen
|
bc7f02156b
|
JS: replace class with two predicates (and improve alert message)
|
2020-06-11 13:20:46 +02:00 |
|