Erik Krogh Kristensen
|
46959234b7
|
Merge pull request #6288 from erik-krogh/emptyRedos
JS/Python: Fix FP in redos related to empty lookaheads
|
2021-08-16 13:48:22 +02:00 |
|
Asger Feldthaus
|
cb0075f15a
|
JS: Remove use of deprecated API
|
2021-08-12 09:30:43 +02:00 |
|
CodeQL CI
|
8fe2a43fd9
|
Merge pull request #6433 from asgerf/js/tainted-url-suffix
Approved by erik-krogh
|
2021-08-12 00:28:46 -07:00 |
|
Asger Feldthaus
|
b9b10af9b5
|
JS: Tolerate parse errors in test due to speculative parsing
|
2021-08-11 12:54:22 +02:00 |
|
Asger Feldthaus
|
65b44248f8
|
JS: Autoformat
|
2021-08-11 12:50:54 +02:00 |
|
Asger Feldthaus
|
4f4f524937
|
JS: Add test for upward traversal
|
2021-08-11 12:50:54 +02:00 |
|
Asger Feldthaus
|
b7339348ef
|
JS: Add tests for EJS includes
|
2021-08-11 12:50:54 +02:00 |
|
Asger Feldthaus
|
b1cadc8ae7
|
JS: Add test for AngularJS sinks
|
2021-08-11 12:50:54 +02:00 |
|
Asger Feldthaus
|
e61d534c59
|
JS: Add ambiguity test for template file resolution
|
2021-08-11 12:50:54 +02:00 |
|
Asger Feldthaus
|
e8d10b983e
|
JS: Tests for template file resolution
|
2021-08-11 12:50:54 +02:00 |
|
Asger Feldthaus
|
28fe8da37c
|
JS: Add similar test for .njk file
|
2021-08-11 12:50:54 +02:00 |
|
Asger Feldthaus
|
1444ec5255
|
JS: Add similar test for hbs
|
2021-08-11 12:50:54 +02:00 |
|
Asger Feldthaus
|
7045fb4679
|
JS: Expand on test
|
2021-08-11 12:50:54 +02:00 |
|
Asger Feldthaus
|
14bada4bbe
|
JS: Model consolidate and factor in template syntax from call site
|
2021-08-11 12:36:35 +02:00 |
|
Erik Krogh Kristensen
|
01a202fa10
|
fix cfg and dataflow for logical compound assignments
|
2021-08-10 12:17:59 +02:00 |
|
Asger Feldthaus
|
d83f5a9cd7
|
JS: Update StringConcatenation tests after handling 0-arg join calls
|
2021-08-10 08:56:36 +02:00 |
|
Asger Feldthaus
|
f1bcfa287b
|
JS: Add more tests
|
2021-08-10 08:55:03 +02:00 |
|
Asger Feldthaus
|
2836d465e4
|
JS: Update locations in Angular2 test
|
2021-08-09 11:03:15 +02:00 |
|
Asger Feldthaus
|
00f4694616
|
JS: Recognize methods returning DOM objects
|
2021-08-04 16:25:56 +02:00 |
|
CodeQL CI
|
07f6ce7f3b
|
Merge pull request #6398 from erik-krogh/authHeader
Approved by esbena
|
2021-08-03 02:04:35 -07:00 |
|
CodeQL CI
|
394d3349ac
|
Merge pull request #6213 from asgerf/js/vuex
Approved by erik-krogh
|
2021-08-03 01:49:06 -07:00 |
|
Erik Krogh Kristensen
|
87c0c60c22
|
don't report dummy authentication headers as hardcoded-crendentials
|
2021-08-02 22:56:14 +02:00 |
|
Erik Krogh Kristensen
|
f719e0ca1b
|
remove nunjucks template URLs from the target-blank query
|
2021-08-02 22:46:59 +02:00 |
|
Erik Krogh Kristensen
|
6da1007f67
|
mark new redos tests correctly
|
2021-07-16 13:37:47 +02:00 |
|
Erik Krogh Kristensen
|
b2b736db10
|
add more tests for non-empty positive lookaheads
|
2021-07-16 13:25:37 +02:00 |
|
Erik Krogh Kristensen
|
178d3de824
|
Merge branch 'main' into logs
|
2021-07-16 11:21:25 +02:00 |
|
CodeQL CI
|
a02a82caac
|
Merge pull request #6284 from erik-krogh/qs
Approved by asgerf
|
2021-07-16 02:11:59 -07:00 |
|
CodeQL CI
|
c1d0e52492
|
Merge pull request #6286 from erik-krogh/mkdirp
Approved by asgerf
|
2021-07-16 02:11:07 -07:00 |
|
CodeQL CI
|
6c2c51a767
|
Merge pull request #6287 from erik-krogh/react-tooltip
Approved by asgerf
|
2021-07-16 02:10:36 -07:00 |
|
CodeQL CI
|
d4fa1f7d96
|
Merge pull request #6295 from erik-krogh/sort-keys
Approved by asgerf
|
2021-07-16 02:09:47 -07:00 |
|
CodeQL CI
|
520337577b
|
Merge pull request #6298 from erik-krogh/ansi-to-html
Approved by asgerf
|
2021-07-16 02:09:03 -07:00 |
|
CodeQL CI
|
f4f8ce0d36
|
Merge pull request #6294 from erik-krogh/arrify
Approved by asgerf
|
2021-07-16 02:08:19 -07:00 |
|
Asger Feldthaus
|
be8c574d5c
|
JS: Add test and comment for access path termination criteria
|
2021-07-16 09:42:59 +02:00 |
|
Asger Feldthaus
|
0247de76af
|
JS: Add a .vue file to vuex test
|
2021-07-16 09:31:47 +02:00 |
|
CodeQL CI
|
b14139f3a0
|
Merge pull request #6261 from max-schaefer/js/module-constructor
Approved by asgerf
|
2021-07-16 00:28:30 -07:00 |
|
Erik Krogh Kristensen
|
2b6790e914
|
update expected output
|
2021-07-15 15:54:51 +02:00 |
|
Erik Krogh Kristensen
|
28b98c1bfa
|
update expected output
|
2021-07-15 15:51:01 +02:00 |
|
Erik Krogh Kristensen
|
ae2fc7171b
|
add a taint step through the ansi-to-html library
|
2021-07-15 14:04:16 +02:00 |
|
Erik Krogh Kristensen
|
aaa8969537
|
add sort-keys as a clone call
|
2021-07-15 13:16:17 +02:00 |
|
Erik Krogh Kristensen
|
d2c74480b9
|
add taint step through flatten libraries
|
2021-07-15 12:36:07 +02:00 |
|
Erik Krogh Kristensen
|
77f4d56cd9
|
add taint step through array-union, array-uniq, and uniq
|
2021-07-15 12:32:29 +02:00 |
|
Erik Krogh Kristensen
|
5ff7d208b7
|
add taint step through arrify
|
2021-07-15 11:24:50 +02:00 |
|
Erik Krogh Kristensen
|
e64f29fe8f
|
add support for Array.prototype.find and polyfills
|
2021-07-15 11:16:06 +02:00 |
|
Erik Krogh Kristensen
|
f6f63e2811
|
add model for the array-from polyfill
|
2021-07-15 10:51:55 +02:00 |
|
Erik Krogh Kristensen
|
80d784e37a
|
add a step over empty lookaheads/lookbehinds
|
2021-07-14 23:40:04 +02:00 |
|
Erik Krogh Kristensen
|
22dfe84ee8
|
add xss sink for react-tooltip
|
2021-07-14 20:03:50 +02:00 |
|
Erik Krogh Kristensen
|
14b26f2a68
|
add mkdirp as a sink for tainted-path
|
2021-07-14 19:32:22 +02:00 |
|
Erik Krogh Kristensen
|
f462c9bb76
|
add taint through the parseqs library
|
2021-07-14 17:22:35 +02:00 |
|
Erik Krogh Kristensen
|
bec1818fc7
|
add taint through the normalize-url library
|
2021-07-14 17:15:14 +02:00 |
|
Erik Krogh Kristensen
|
193ddfc771
|
add taint through the qs library
|
2021-07-14 16:56:51 +02:00 |
|