Alvaro Muñoz
|
e1f05e960d
|
Merge branch 'restify_improvements' of https://github.com/pwntester/codeql into restify_improvements
|
2022-12-14 13:11:13 +01:00 |
|
Alvaro Muñoz
|
a71fc930a6
|
add tests
|
2022-12-14 13:11:02 +01:00 |
|
Alvaro Muñoz
|
701676eea1
|
Update javascript/ql/lib/semmle/javascript/frameworks/Spife.qll
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2022-12-14 10:18:47 +01:00 |
|
Alvaro Muñoz
|
270a4355df
|
format Restify.qll
|
2022-12-13 11:22:24 +01:00 |
|
Alvaro Muñoz
|
4ba3190d29
|
Replace API::Node with DataFlow::Node for Spife's RouteSetup
|
2022-12-13 11:10:04 +01:00 |
|
Alvaro Muñoz
|
469d7f52dc
|
Use fluent API instead of hasPropertyWrite
|
2022-12-12 10:46:50 +01:00 |
|
Alvaro Muñoz
|
1410d2838e
|
Update javascript/ql/lib/semmle/javascript/frameworks/Spife.qll
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2022-12-12 09:54:02 +01:00 |
|
Alvaro Muñoz
|
38b2f537d4
|
Use ReplyCall.super syntax instead of this.(ReplyCall)
|
2022-12-07 16:39:07 +01:00 |
|
Alvaro Muñoz
|
af015d3d30
|
restoring previous casts to avoid super type ambiguity
|
2022-12-07 10:39:58 +01:00 |
|
Alvaro Muñoz
|
407df37a74
|
Add feedback from Code review
|
2022-12-07 10:36:44 +01:00 |
|
Alvaro Muñoz
|
3e92b4c596
|
Apply suggestions from code review
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2022-12-07 10:29:29 +01:00 |
|
Alvaro Muñoz
|
9830d2bebc
|
Format Restify.qll
|
2022-10-25 12:53:44 +02:00 |
|
Alvaro Muñoz
|
a80b691358
|
Remove unnecessary TaggedTemplateEntryPoint
|
2022-10-25 11:44:45 +02:00 |
|
Alvaro Muñoz
|
37ea3f23f1
|
Refactored ReplySource to ReplyCall. Got rid of unnecessary ref()
|
2022-10-25 11:42:48 +02:00 |
|
Alvaro Muñoz
|
742e4aa471
|
Apply suggestions from code review
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2022-10-24 16:17:11 +02:00 |
|
Alvaro Muñoz
|
c7ac237968
|
Update test results after merging new XSS improvements
|
2022-10-19 23:41:37 +02:00 |
|
Alvaro Muñoz
|
c10087b9a3
|
Merge branch 'restify_improvements' of https://github.com/pwntester/codeql into restify_improvements
|
2022-10-19 22:18:29 +02:00 |
|
Alvaro Muñoz
|
009403b61e
|
Add QLDoc for FormatterSetup.getAFormatterHandler
|
2022-10-19 22:18:13 +02:00 |
|
Alvaro Muñoz
|
2ad5a70cf1
|
Merge branch 'main' into restify_improvements
|
2022-10-19 21:57:37 +02:00 |
|
Alvaro Muñoz
|
245be44eac
|
Merge branch 'main' into javascript_xss_improvements
|
2022-10-19 18:18:19 +02:00 |
|
Alvaro Muñoz
|
976dd7f99f
|
Fix format errors
|
2022-10-19 18:14:25 +02:00 |
|
Alvaro Muñoz
|
31d271b8e1
|
Fix format errors
|
2022-10-19 17:32:34 +02:00 |
|
Henry Mercer
|
6a12d676b8
|
Merge pull request #10878 from jsoref/spelling-ml
Spelling ml
|
2022-10-19 16:28:06 +01:00 |
|
Henry Mercer
|
3afb9c1b3b
|
Merge pull request #10845 from github/henrymercer/remove-worsening-queries
ATM: Remove worsening-based queries
|
2022-10-19 10:05:53 +01:00 |
|
Josh Soref
|
d722448796
|
spelling: injection
Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>
|
2022-10-19 04:27:37 -04:00 |
|
Josh Soref
|
a4beafbe44
|
spelling: classifier
Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>
|
2022-10-19 04:27:37 -04:00 |
|
Alvaro Muñoz
|
b79f7f3e95
|
Address code review comments
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2022-10-18 21:42:15 +02:00 |
|
Alvaro Muñoz
|
6ab62da015
|
Add Restify/Spife support
|
2022-10-18 21:41:34 +02:00 |
|
github-actions[bot]
|
fa274e4375
|
ATM: Update ML model to 0.2.1-2022-09-06-08h55m54s.bubbly-basin-xpztl8fh.f3c3c9360a727959e428ecc6932257e6a546dc65d8a9baac525a49247123822d
|
2022-10-18 11:53:42 +00:00 |
|
Erik Krogh Kristensen
|
71135da7ff
|
Merge pull request #10768 from erik-krogh/fixFileLoops
JS: fix that js/file-system-race could have FPs related to loops
|
2022-10-17 12:01:55 +02:00 |
|
Henry Mercer
|
c0ac7ad7db
|
Remove query for worsening-based classifier evaluation
|
2022-10-14 15:35:43 +01:00 |
|
Henry Mercer
|
63ab295a46
|
Remove queries for worsening-based evaluation
|
2022-10-14 15:18:19 +01:00 |
|
erik-krogh
|
a6c83a7b14
|
add change-note
|
2022-10-14 09:20:33 +02:00 |
|
Alvaro Muñoz
|
41fea776e8
|
Do not discard XSS sinks when non-content-type headers are local to the sendArgument expression
|
2022-10-13 17:50:43 +02:00 |
|
Josh Soref
|
45d1e3f9b2
|
spelling: representation
Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>
|
2022-10-13 10:56:41 -04:00 |
|
Josh Soref
|
124c5544cf
|
spelling: predicates
Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>
|
2022-10-13 10:56:41 -04:00 |
|
Josh Soref
|
52a3e3c2fd
|
spelling: heuristic
Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>
|
2022-10-13 10:56:41 -04:00 |
|
Josh Soref
|
5d94733078
|
spelling: ambiguously
Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>
|
2022-10-13 10:51:25 -04:00 |
|
Alvaro Muñoz
|
744cea9baa
|
add tests
|
2022-10-13 15:19:29 +02:00 |
|
Alvaro Muñoz
|
468628525e
|
Change to camelcase
|
2022-10-13 12:18:07 +02:00 |
|
Alvaro Muñoz
|
ea8edb8408
|
initial tests
|
2022-10-13 11:32:21 +02:00 |
|
Erik Krogh Kristensen
|
10aab81f42
|
Merge pull request #10799 from jsoref/spelling-nfautils
ReDoS: Spelling nfautils
|
2022-10-12 23:09:06 +02:00 |
|
Henry Mercer
|
c3af41b907
|
Merge pull request #10781 from github/codeql-ci/js/ml-powered-pack-release-0.3.5
JS: Bump version numbers of ML-powered packs after 0.3.5 release
|
2022-10-12 20:20:31 +01:00 |
|
Josh Soref
|
09c8a98761
|
spelling: representation
Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>
|
2022-10-12 15:20:26 -04:00 |
|
Josh Soref
|
bb1ce8973a
|
spelling: repeatable
Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>
|
2022-10-12 15:20:24 -04:00 |
|
Josh Soref
|
adb8860b9b
|
spelling: pattern
Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>
|
2022-10-12 15:20:24 -04:00 |
|
Josh Soref
|
c7ae0728f3
|
spelling: javascript
Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>
|
2022-10-12 15:02:00 -04:00 |
|
Josh Soref
|
98b317d1a5
|
spelling: escape
Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>
|
2022-10-12 15:02:00 -04:00 |
|
Josh Soref
|
370da943dc
|
spelling: abcdefghijklmnopqrstuvwxyz
Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>
|
2022-10-12 15:02:00 -04:00 |
|
Josh Soref
|
9d6ea28448
|
spelling: the
Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>
|
2022-10-12 04:40:26 -04:00 |
|