Michael Nebel
|
6d330891db
|
Merge pull request #20395 from michaelnebel/javascript/code-quality-extended
JS: Add most `medium` precision queries to the `code-quality-extended` suite.
|
2025-09-17 13:47:02 +02:00 |
|
Napalys Klicius
|
7affcf40c2
|
JS: Add variableValues to the previous summaryModel to enchance the flow.
|
2025-09-17 12:24:14 +02:00 |
|
Napalys Klicius
|
6c18b4de40
|
JS: Add test case for graph ql variableValues injection
|
2025-09-17 12:21:21 +02:00 |
|
github-actions[bot]
|
4e8343664f
|
Post-release preparation for codeql-cli-2.23.1
|
2025-09-17 10:13:40 +00:00 |
|
Napalys Klicius
|
6d461d6b50
|
JS: Add change note
|
2025-09-17 11:48:49 +02:00 |
|
Napalys Klicius
|
4282005e32
|
JS: Add summary model for graphql's rootValue
|
2025-09-17 11:48:44 +02:00 |
|
Napalys Klicius
|
a6d728a66d
|
JS: Add test case with missing alert using graphql
|
2025-09-17 11:23:49 +02:00 |
|
Napalys Klicius
|
ca667b5131
|
JS: fix test expectations from rebasing
|
2025-09-17 10:24:45 +02:00 |
|
Napalys Klicius
|
4df8db0d7e
|
Renamed AWS-V3-Common to @aws-sdk/client.Client
|
2025-09-17 10:21:29 +02:00 |
|
Napalys Klicius
|
10f3a83fcb
|
Fixed model type names
Co-authored-by: asgerf <asgerf@users.noreply.github.com>
|
2025-09-17 10:21:23 +02:00 |
|
Napalys Klicius
|
9ca4773227
|
Added modeling for CreatePreparedStatementCommand
|
2025-09-17 10:21:10 +02:00 |
|
Napalys Klicius
|
872b6d8bee
|
Added test case for CreatePreparedStatementCommand
|
2025-09-17 10:21:01 +02:00 |
|
Napalys Klicius
|
b89e70b5a0
|
Added test cases for aws sources
|
2025-09-17 10:20:52 +02:00 |
|
Napalys Klicius
|
801a34f6a1
|
Moved typeModel at the start of the file
|
2025-09-17 10:20:24 +02:00 |
|
Napalys Klicius
|
9beac51586
|
Unified aws-db modeling into singular file
|
2025-09-17 10:20:10 +02:00 |
|
Napalys Klicius
|
5b31350e83
|
Added tests and modeling of database-access-result
|
2025-09-17 10:20:01 +02:00 |
|
Napalys Klicius
|
93d9ae73b7
|
Updated change note
|
2025-09-17 10:19:52 +02:00 |
|
Napalys Klicius
|
e5f02852e1
|
Added modeling of rds v2 and v3 for sql injections
|
2025-09-17 10:19:22 +02:00 |
|
Napalys Klicius
|
5b5c17100c
|
Added test cases for client-rds-data for sql injections
|
2025-09-17 10:19:10 +02:00 |
|
Napalys Klicius
|
0e6bac73a7
|
Added modeling of athena v2 and v3 for sql injections
|
2025-09-17 10:18:58 +02:00 |
|
Napalys Klicius
|
af97b0edc2
|
Added test cases for athena v2 and v3 for sql injections
|
2025-09-17 10:16:38 +02:00 |
|
Napalys Klicius
|
ee1af432fe
|
Added modeling of client-s3 v2 and v3
|
2025-09-17 10:16:25 +02:00 |
|
Napalys Klicius
|
5e6118ef3f
|
Added test cases for client-s v2 and v3 sql injection
|
2025-09-17 10:15:43 +02:00 |
|
Napalys Klicius
|
1149617f7b
|
Added change note
|
2025-09-17 10:15:32 +02:00 |
|
Napalys Klicius
|
06ab918985
|
Added modeling for V2 of dynamoDB
|
2025-09-17 10:15:19 +02:00 |
|
Napalys Klicius
|
ae2e8b1292
|
Added modeling of dynamodb v3 for sql injections
|
2025-09-17 10:13:24 +02:00 |
|
Napalys Klicius
|
0a3343a07d
|
Added test cases for v2 and v3 sql injection of dynamodb
|
2025-09-17 10:11:31 +02:00 |
|
github-actions[bot]
|
02a1b1efcb
|
Release preparation for version 2.23.1
|
2025-09-16 14:14:42 +00:00 |
|
Asger F
|
7670a2bd77
|
Merge pull request #20375 from asgerf/js/promise-try
JS: Support Promise.try and Array.prototype.with
|
2025-09-16 14:44:07 +02:00 |
|
Napalys Klicius
|
97a11de1e3
|
Merge pull request #20435 from Napalys/js/promisification_modeling
JS: Promisification library modeling and enhance flow
|
2025-09-16 14:07:53 +02:00 |
|
Asger F
|
edf79a3730
|
JS: Change note
|
2025-09-16 13:53:31 +02:00 |
|
Asger F
|
0b900711bf
|
Update javascript/ql/lib/semmle/javascript/frameworks/Express.qll
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
|
2025-09-16 13:48:26 +02:00 |
|
Napalys Klicius
|
49ccb8ce2b
|
JS: Simplify exist clause to use Promisify::PromisifyAllCall instead of DataFlow::SourceNode
|
2025-09-16 13:13:15 +02:00 |
|
Asger F
|
429c4eac96
|
JS: Add support for Array.prototype.with
Note: This was authored by Copilot
|
2025-09-16 13:06:59 +02:00 |
|
Asger F
|
ee78b7dc96
|
JS: Add support for Promise.try
|
2025-09-16 13:06:57 +02:00 |
|
Asger F
|
45eff3dac8
|
Merge pull request #20399 from asgerf/js/default-interop2
JS: Refactor handling of ambiguous default imports
|
2025-09-16 13:02:22 +02:00 |
|
Asger F
|
78bfdfd931
|
Merge pull request #20390 from asgerf/post-update-consistency
DataFlow: Permit local flow between post-update nodes
|
2025-09-16 13:00:29 +02:00 |
|
Asger F
|
65102a073a
|
Merge pull request #19770 from trailofbits/VF/async-package-improvements
Improve data flow in the `async` package
|
2025-09-16 08:55:52 +02:00 |
|
Asger F
|
f587273828
|
Merge pull request #19768 from trailofbits/VF/lodash-group-by
Add lodash GroupBy as taint step
|
2025-09-16 08:55:13 +02:00 |
|
Chris Smowton
|
c375f24598
|
Merge pull request #20423 from smowton/smowton/fix/length-comparison-off-by-one-fp
JS: Recognise that a less-than test is as good as a non-equal test for mitigating off-by-one array access
|
2025-09-15 18:24:45 +01:00 |
|
Napalys Klicius
|
278a1efb4b
|
JS: Add change note
|
2025-09-15 18:21:45 +02:00 |
|
Napalys Klicius
|
3a75500f54
|
JS: Add modeling for call-me-maybe
|
2025-09-15 17:15:31 +02:00 |
|
Napalys Klicius
|
0d23ab07db
|
JS: Add data flow modeling for promisified user-defined functions
|
2025-09-15 17:13:13 +02:00 |
|
Napalys Klicius
|
2c6db00cbc
|
JS: Add modeling for util promisify*
|
2025-09-15 17:09:28 +02:00 |
|
Napalys Klicius
|
e002f2088f
|
JS: Add modeling for es6-promisify
|
2025-09-15 17:04:34 +02:00 |
|
Napalys Klicius
|
35c75c00ba
|
JS: Add modeling for @gar/promisify
|
2025-09-15 16:58:11 +02:00 |
|
Napalys Klicius
|
312471e9db
|
JS: Add modeling for @google-cloud/promisify
|
2025-09-15 16:55:27 +02:00 |
|
Napalys Klicius
|
d37425ae3e
|
JS: Treat promisify(obj).member as obj.member
|
2025-09-15 16:51:19 +02:00 |
|
Napalys Klicius
|
22b61852a1
|
JS: Add modeling for thenify-all
|
2025-09-15 16:31:14 +02:00 |
|
Napalys Klicius
|
d6a14e63ba
|
JS: Add test cases for promisification libraries.
|
2025-09-15 16:21:12 +02:00 |
|