yoff
|
75bd4a7a12
|
javascript: add MaD model
- consider if the model is in the right place
- consider if the barrier kind (sink kind) is the appropriate one
|
2026-01-22 17:30:24 +01:00 |
|
yoff
|
da2f77d615
|
javascript: remove sanitizer to be replaced by model
|
2026-01-22 17:30:24 +01:00 |
|
Asger F
|
2892ab61ae
|
JS: Make sure a file is not seen as minified
|
2026-01-14 11:40:01 +01:00 |
|
Asger F
|
84f6b6f67a
|
JS: Accept test change due to file no longer being extracted
|
2026-01-14 11:40:01 +01:00 |
|
Asger F
|
e430aa97f3
|
Merge pull request #20916 from asgerf/js/next-folders2
JS: Handle Next.js files named 'page' or 'route'
|
2026-01-14 11:10:57 +01:00 |
|
Asger F
|
ca52fe59e8
|
Merge pull request #20918 from asgerf/js/response-default-content-type
JS: Handle default 'content-type' header in Response() objects
|
2026-01-13 10:34:40 +01:00 |
|
tesseractjh
|
2e840dcd5f
|
Add use cache directives
|
2025-12-09 08:59:16 +01:00 |
|
Asger F
|
7c0243fc6d
|
Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
|
2025-11-27 13:18:11 +01:00 |
|
Asger F
|
cc7bf4e880
|
JS: Handle default 'content-type' header in Response() objects
|
2025-11-26 13:49:48 +01:00 |
|
Asger F
|
037f354abf
|
JS: Update another expected file
|
2025-11-26 11:42:39 +01:00 |
|
Asger F
|
f0ecf1599c
|
JS: Add test with file named 'page'
|
2025-11-26 11:16:12 +01:00 |
|
Asger F
|
e54789d1bd
|
JS: Recognise route.ts outside api folder
|
2025-11-26 11:16:11 +01:00 |
|
Asger F
|
f52f5b63e6
|
JS: Add test with route.ts outside 'api'
|
2025-11-26 11:16:09 +01:00 |
|
Asger F
|
5b4e114955
|
JS: Add test
|
2025-11-25 16:04:30 +01:00 |
|
Asger F
|
8d49f26f3d
|
Merge pull request #20397 from asgerf/js/build-artifact-leak-fp
JS: Fix FP in js/build-artifact-leak when keys come from an array of constants
|
2025-10-28 06:40:13 +01:00 |
|
Napalys Klicius
|
6cfc950159
|
JS: Model GraphQLObjectType resolve params as sources
|
2025-09-19 14:39:36 +02:00 |
|
Napalys Klicius
|
d88bc8e408
|
JS: Add test case for GraphQLObjectType
|
2025-09-19 14:23:40 +02:00 |
|
Napalys Klicius
|
4f8166a661
|
Merge pull request #20450 from Napalys/js/graph-ql-ench
JS: Improve graphql flow
|
2025-09-17 16:32:01 +02:00 |
|
Napalys Klicius
|
7affcf40c2
|
JS: Add variableValues to the previous summaryModel to enchance the flow.
|
2025-09-17 12:24:14 +02:00 |
|
Napalys Klicius
|
6c18b4de40
|
JS: Add test case for graph ql variableValues injection
|
2025-09-17 12:21:21 +02:00 |
|
Napalys Klicius
|
4282005e32
|
JS: Add summary model for graphql's rootValue
|
2025-09-17 11:48:44 +02:00 |
|
Napalys Klicius
|
a6d728a66d
|
JS: Add test case with missing alert using graphql
|
2025-09-17 11:23:49 +02:00 |
|
Napalys Klicius
|
ca667b5131
|
JS: fix test expectations from rebasing
|
2025-09-17 10:24:45 +02:00 |
|
Napalys Klicius
|
9ca4773227
|
Added modeling for CreatePreparedStatementCommand
|
2025-09-17 10:21:10 +02:00 |
|
Napalys Klicius
|
872b6d8bee
|
Added test case for CreatePreparedStatementCommand
|
2025-09-17 10:21:01 +02:00 |
|
Napalys Klicius
|
b89e70b5a0
|
Added test cases for aws sources
|
2025-09-17 10:20:52 +02:00 |
|
Napalys Klicius
|
5b31350e83
|
Added tests and modeling of database-access-result
|
2025-09-17 10:20:01 +02:00 |
|
Napalys Klicius
|
e5f02852e1
|
Added modeling of rds v2 and v3 for sql injections
|
2025-09-17 10:19:22 +02:00 |
|
Napalys Klicius
|
5b5c17100c
|
Added test cases for client-rds-data for sql injections
|
2025-09-17 10:19:10 +02:00 |
|
Napalys Klicius
|
0e6bac73a7
|
Added modeling of athena v2 and v3 for sql injections
|
2025-09-17 10:18:58 +02:00 |
|
Napalys Klicius
|
af97b0edc2
|
Added test cases for athena v2 and v3 for sql injections
|
2025-09-17 10:16:38 +02:00 |
|
Napalys Klicius
|
ee1af432fe
|
Added modeling of client-s3 v2 and v3
|
2025-09-17 10:16:25 +02:00 |
|
Napalys Klicius
|
5e6118ef3f
|
Added test cases for client-s v2 and v3 sql injection
|
2025-09-17 10:15:43 +02:00 |
|
Napalys Klicius
|
06ab918985
|
Added modeling for V2 of dynamoDB
|
2025-09-17 10:15:19 +02:00 |
|
Napalys Klicius
|
ae2e8b1292
|
Added modeling of dynamodb v3 for sql injections
|
2025-09-17 10:13:24 +02:00 |
|
Napalys Klicius
|
0a3343a07d
|
Added test cases for v2 and v3 sql injection of dynamodb
|
2025-09-17 10:11:31 +02:00 |
|
Napalys Klicius
|
97a11de1e3
|
Merge pull request #20435 from Napalys/js/promisification_modeling
JS: Promisification library modeling and enhance flow
|
2025-09-16 14:07:53 +02:00 |
|
Napalys Klicius
|
3a75500f54
|
JS: Add modeling for call-me-maybe
|
2025-09-15 17:15:31 +02:00 |
|
Napalys Klicius
|
0d23ab07db
|
JS: Add data flow modeling for promisified user-defined functions
|
2025-09-15 17:13:13 +02:00 |
|
Napalys Klicius
|
2c6db00cbc
|
JS: Add modeling for util promisify*
|
2025-09-15 17:09:28 +02:00 |
|
Napalys Klicius
|
e002f2088f
|
JS: Add modeling for es6-promisify
|
2025-09-15 17:04:34 +02:00 |
|
Napalys Klicius
|
35c75c00ba
|
JS: Add modeling for @gar/promisify
|
2025-09-15 16:58:11 +02:00 |
|
Napalys Klicius
|
312471e9db
|
JS: Add modeling for @google-cloud/promisify
|
2025-09-15 16:55:27 +02:00 |
|
Napalys Klicius
|
d37425ae3e
|
JS: Treat promisify(obj).member as obj.member
|
2025-09-15 16:51:19 +02:00 |
|
Napalys Klicius
|
d6a14e63ba
|
JS: Add test cases for promisification libraries.
|
2025-09-15 16:21:12 +02:00 |
|
Chris Smowton
|
4fb133a43d
|
Recognise that a less-than test is as good as a non-equal test for mitigating off-by-one array access
|
2025-09-12 14:32:07 +01:00 |
|
Asger F
|
2a4d6830ec
|
JS: An array of constants should be considered "filtered"
|
2025-09-10 11:07:32 +02:00 |
|
Asger F
|
602dae0592
|
JS: Add test showing FP
|
2025-09-10 10:58:34 +02:00 |
|
Asger F
|
36e18c2a89
|
JS: Enable inline expectations in BuildArtifactLeak
The tests already have the annotations, it just seems to have been disable by accident
|
2025-09-10 10:56:34 +02:00 |
|
Napalys Klicius
|
b2feaaceea
|
Merge branch 'main' into js/move-cors-query-from-experimental
|
2025-09-05 12:11:09 +02:00 |
|