Michael Nebel
|
0f146f1486
|
Javascript: Move test utilities into the query pack.
|
2024-12-12 13:54:23 +01:00 |
|
github-actions[bot]
|
cf71a1525b
|
Post-release preparation for codeql-cli-2.20.0
|
2024-12-04 18:36:17 +00:00 |
|
github-actions[bot]
|
96564b7128
|
Release preparation for version 2.20.0
|
2024-12-04 16:01:14 +00:00 |
|
Henry Mercer
|
963f084d87
|
Merge branch 'main' into henrymercer/merge-back-rc-3.16
|
2024-12-04 13:39:10 +00:00 |
|
Napalys
|
9d4e737bc2
|
JS: follow proper code standards for get predicates
Co-authored-by: asgerf <asgerf@github.com>
|
2024-11-29 11:32:10 +01:00 |
|
Napalys
|
3171f38cdd
|
JS: fixed bad alert messages when it came to incomplete sanitization for new RegExp objects
|
2024-11-29 11:14:45 +01:00 |
|
Napalys
|
98fd97799c
|
JS: imcomplete sanization now handles properly maybe global
|
2024-11-28 11:26:50 +01:00 |
|
Napalys
|
1ae174849f
|
JS: incomplete sanitization now also works with RegExp objects
|
2024-11-28 11:26:48 +01:00 |
|
Napalys Klicius
|
d6372aebc7
|
Update javascript/ql/src/Security/CWE-178/CaseSensitiveMiddlewarePath.ql
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2024-11-25 12:12:12 +01:00 |
|
Napalys
|
e38b63ebcd
|
JS: previously js/case-sensitive-middleware-path was not taking into consideration unknown flags
|
2024-11-25 11:56:06 +01:00 |
|
Alexander Eyers-Taylor
|
c0474c4e45
|
Revert "Revert "Post-release preparation for codeql-cli-2.19.4""
|
2024-11-21 15:37:52 +00:00 |
|
Alexander Eyers-Taylor
|
4effe9e364
|
Revert "Post-release preparation for codeql-cli-2.19.4"
|
2024-11-21 14:43:15 +00:00 |
|
github-actions[bot]
|
3909df75dc
|
Post-release preparation for codeql-cli-2.19.4
|
2024-11-19 17:54:03 +00:00 |
|
github-actions[bot]
|
9783a11565
|
Release preparation for version 2.19.4
|
2024-11-19 16:21:37 +00:00 |
|
Napalys
|
a28fc8e772
|
JS: Add: Use of returnless function support for findLast and findLastIndex
|
2024-11-15 14:44:25 +01:00 |
|
Napalys Klicius
|
c8c15a0899
|
Merge pull request #17910 from Napalys/napalys/matchAll-support
JS: Support for matchAll
|
2024-11-14 15:36:20 +01:00 |
|
Mikaël Barbero
|
881fe0ba57
|
fix: add "actions" tag to ActionsArtifactLeak
Similar to javascript/ql/src/Security/CWE-094/ExpressionInjection.ql
|
2024-11-05 15:58:46 +01:00 |
|
Napalys Klicius
|
5e8b1b061f
|
Update javascript/ql/src/Security/CWE-020/MissingRegExpAnchor.ql
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2024-11-05 10:29:22 +01:00 |
|
Napalys Klicius
|
7825a46085
|
Merge branch 'github:main' into napalys/matchAll-support
|
2024-11-05 09:31:30 +01:00 |
|
Napalys
|
ccee34d6d3
|
Added support for matchAll in CWE-020 including new test cases
|
2024-11-05 08:51:24 +01:00 |
|
github-actions[bot]
|
f107d16b4e
|
Post-release preparation for codeql-cli-2.19.3
|
2024-11-04 17:20:08 +00:00 |
|
github-actions[bot]
|
cc7b724123
|
Release preparation for version 2.19.3
|
2024-11-04 16:37:28 +00:00 |
|
Rasmus Wriedt Larsen
|
dc8e645594
|
JS: Convert remaining queries to use ActiveThreatModelSourceAsSource
|
2024-11-01 10:47:10 +01:00 |
|
github-actions[bot]
|
079ab77a38
|
Post-release preparation for codeql-cli-2.19.2
|
2024-10-15 12:16:59 +00:00 |
|
github-actions[bot]
|
255f55cf1a
|
Release preparation for version 2.19.2
|
2024-10-15 10:29:25 +00:00 |
|
github-actions[bot]
|
e97878ed63
|
Post-release preparation for codeql-cli-2.19.1
|
2024-09-30 19:49:00 +00:00 |
|
github-actions[bot]
|
455c8c5953
|
Release preparation for version 2.19.1
|
2024-09-30 17:59:48 +00:00 |
|
github-actions[bot]
|
79be301984
|
Post-release preparation for codeql-cli-2.19.0
|
2024-09-16 14:09:32 +00:00 |
|
Chris Smowton
|
be02864281
|
Copyedit
|
2024-09-16 12:25:49 +01:00 |
|
github-actions[bot]
|
acdafd9646
|
Release preparation for version 2.19.0
|
2024-09-16 10:56:10 +00:00 |
|
Dave Bartolomeo
|
485fc04029
|
Initial merge from main
|
2024-09-15 08:55:31 -04:00 |
|
Alvaro Muñoz
|
061d58ae4a
|
Update javascript/ql/src/change-notes/2024-09-06-new-actions-artifact-leak-query.md
Co-authored-by: Asger F <asgerf@github.com>
|
2024-09-10 22:18:04 +02:00 |
|
github-actions[bot]
|
97edff3f70
|
Post-release preparation for codeql-cli-2.18.4
|
2024-09-09 18:45:46 +00:00 |
|
github-actions[bot]
|
91537cdf9a
|
Release preparation for version 2.18.4
|
2024-09-09 16:08:48 +00:00 |
|
Alvaro Muñoz
|
d34a0ba306
|
Add change note
|
2024-09-06 23:28:57 +02:00 |
|
Alvaro Muñoz
|
5d1da861a2
|
fix: Use YamlScalar for booleans
|
2024-09-06 23:21:41 +02:00 |
|
Alvaro Muñoz
|
5df3af2272
|
Fix alert message
|
2024-09-06 23:06:57 +02:00 |
|
Alvaro Muñoz
|
d9e8792d33
|
[javascript] Query to detect GITHUB_TOKEN leaked in artifacts
|
2024-09-06 22:55:58 +02:00 |
|
Henry Mercer
|
3490067316
|
Merge branch 'main' into henrymercer/rc-3.15-mergeback
|
2024-08-29 19:48:01 +01:00 |
|
Asger F
|
a1688f6a1a
|
Merge pull request #17240 from knewbury01/knewbury01/fix-helmetrequiredsetting-model
Update JS helmet model structure
|
2024-08-22 11:59:28 +02:00 |
|
github-actions[bot]
|
0724fd7ce2
|
Post-release preparation for codeql-cli-2.18.3
|
2024-08-21 18:25:54 +00:00 |
|
github-actions[bot]
|
17cd9624fb
|
Release preparation for version 2.18.3
|
2024-08-21 17:13:52 +00:00 |
|
Asger F
|
467256d465
|
JS: Add change note
|
2024-08-16 11:06:59 +02:00 |
|
Kristen Newbury
|
e84dda4fa6
|
Update JS helmet model structure
|
2024-08-15 16:08:48 -04:00 |
|
github-actions[bot]
|
cc6d87c276
|
Post-release preparation for codeql-cli-2.18.2
|
2024-08-08 12:56:21 +00:00 |
|
github-actions[bot]
|
019da8c287
|
Release preparation for version 2.18.2
|
2024-08-07 14:02:38 +00:00 |
|
Alexander Eyers-Taylor
|
46577b585e
|
Revert "Release preparation for version 2.18.2"
|
2024-08-07 14:24:37 +01:00 |
|
github-actions[bot]
|
c14ba0e4bd
|
Release preparation for version 2.18.2
|
2024-08-06 12:46:15 +00:00 |
|
github-actions[bot]
|
49cc8f8ff8
|
Post-release preparation for codeql-cli-2.18.1
|
2024-07-22 22:00:48 +00:00 |
|
github-actions[bot]
|
368bcb684a
|
Release preparation for version 2.18.1
|
2024-07-22 21:30:50 +00:00 |
|