Esben Sparre Andreasen
|
fad55e0035
|
Remove additional path-injection sinks
|
2022-05-16 08:52:50 +00:00 |
|
Esben Sparre Andreasen
|
cd41d9d14a
|
Remove 2020 sinks from TaintedPath.ql
|
2022-05-16 08:52:50 +00:00 |
|
Stephan Brandauer
|
0bd9e9f298
|
add handlebars taint step
|
2022-03-24 11:46:16 +01:00 |
|
Erik Krogh Kristensen
|
28ba78cb76
|
add explicit this
|
2022-02-08 12:20:21 +01:00 |
|
Erik Krogh Kristensen
|
d73b2effa0
|
rename maybeGetJoinArg maybeGetPathSuffix
|
2022-02-08 10:42:06 +01:00 |
|
Erik Krogh Kristensen
|
ca5f91e587
|
recognize more startswith sanitizers for path-injection queries
|
2022-02-07 14:19:13 +01:00 |
|
Erik Krogh Kristensen
|
0ff36cd083
|
Merge branch 'main' into explicit-this
|
2021-11-13 21:01:25 +01:00 |
|
Asger Feldthaus
|
f14f9449ee
|
JS: Use getAMatchedString instead of getConstantString
|
2021-11-08 15:35:35 +01:00 |
|
Asger Feldthaus
|
971f032b5f
|
JS: Autoformat
|
2021-11-02 14:12:05 +01:00 |
|
Asger Feldthaus
|
46bd3e58a3
|
JS: Switch to instanceof base type
|
2021-11-02 14:12:05 +01:00 |
|
Asger Feldthaus
|
5f4c1dd19b
|
JS: Support regexp-based path traversal check
|
2021-11-02 14:12:05 +01:00 |
|
Erik Krogh Kristensen
|
db40ccae81
|
add explicit this to all member calls
|
2021-11-01 09:51:15 +01:00 |
|
Erik Krogh Kristensen
|
a3c55c2aec
|
use set literal instead of big disjunction of literals
|
2021-10-26 12:55:25 +02:00 |
|
Andrew Eisenberg
|
45d1fa7f01
|
Packaging: Rafactor Javascript core libraries
Extract the external facing `qll` files into the codeql/javascript-all
query pack.
|
2021-08-25 12:15:56 -07:00 |
|