Stephan Brandauer
|
6722c17bb0
|
JS: Functionality from untrusted sources query (CWE-830)
|
2022-02-22 11:41:52 +01:00 |
|
Asger F
|
02c4966109
|
Merge pull request #7878 from asgerf/dot-separated-access-paths
Shared: Switch to dot-separated access paths in summary specs
|
2022-02-21 13:29:09 +01:00 |
|
Esben Sparre Andreasen
|
1d437dd722
|
Merge pull request #8043 from github/esbena/sharpen-hardcoded-credentials
JS: Sharpen hardcoded credentials
|
2022-02-21 10:02:58 +01:00 |
|
Erik Krogh Kristensen
|
5f9bd7a4a1
|
Merge pull request #7984 from erik-krogh/fix-ql-for-ql-js
JS: fix most ql-for-ql warnings
|
2022-02-21 09:15:06 +01:00 |
|
Asger Feldthaus
|
d7f07167ac
|
Shared: Remove getLastToken again
|
2022-02-21 08:21:53 +01:00 |
|
Asger Feldthaus
|
2c2a82a070
|
Shared: allow spaces between arguments in a token
|
2022-02-21 08:21:53 +01:00 |
|
Asger Feldthaus
|
7fcbdbeada
|
Shared: sync AccessPathSyntax.qll and FlowSummaryImpl.qll
|
2022-02-21 08:21:52 +01:00 |
|
Asger Feldthaus
|
2907d53e17
|
Shared: sync AccessPathSyntax.qll and FlowSummaryImpl.qll
|
2022-02-21 08:21:52 +01:00 |
|
Asger Feldthaus
|
c189df2341
|
Revert "JS: Add support for " of " syntax to help during transition"
This reverts commit 9bf522b3048c3b11f7e6d734ed797a613614a095.
|
2022-02-21 08:21:51 +01:00 |
|
Asger Feldthaus
|
753c557dbe
|
Java: use AccessPathSyntax.qll to parse input/output summary specs
|
2022-02-21 08:16:54 +01:00 |
|
Asger Feldthaus
|
53935db6c6
|
JS: Add support for " of " syntax to help during transition
|
2022-02-21 08:16:54 +01:00 |
|
Asger Feldthaus
|
30254686d8
|
JS: Move ".."-parsing trick into AccessPathSyntax.qll
|
2022-02-21 08:16:54 +01:00 |
|
Asger Feldthaus
|
7c2cff3227
|
JS: Factor out AccessPathSyntax.qll
|
2022-02-21 08:16:54 +01:00 |
|
Asger Feldthaus
|
e2cbf47b16
|
JS: Fix accidental recursion
|
2022-02-21 08:16:53 +01:00 |
|
Esben Sparre Andreasen
|
816d79692b
|
ignore deliberately hardcoded password strings
|
2022-02-16 09:47:01 +01:00 |
|
Asger Feldthaus
|
8b55a24e7c
|
JS: Add url-parse.qs as an alias for the querystringify library
|
2022-02-14 15:29:50 +01:00 |
|
Erik Krogh Kristensen
|
a1c5724be7
|
fix most ql-for-ql warnings in JS
|
2022-02-11 17:57:37 +01:00 |
|
Erik Krogh Kristensen
|
36e02ae9ac
|
Merge pull request #7912 from erik-krogh/moarApi
JS: convert more type-trackers to API-graphs
|
2022-02-11 10:32:45 +01:00 |
|
Erik Krogh Kristensen
|
3791b159fb
|
Merge pull request #7892 from erik-krogh/nanSan
JS: Add a `isNaN` sanitizer, and use it in queries that already had a typeof check
|
2022-02-11 10:13:06 +01:00 |
|
Erik Krogh Kristensen
|
2ffd79d451
|
Merge pull request #7921 from erik-krogh/snapdragon
JS: add model for the snapdragon library
|
2022-02-11 10:10:55 +01:00 |
|
Esben Sparre Andreasen
|
a4447ce372
|
Update javascript/ql/lib/semmle/javascript/frameworks/Snapdragon.qll
|
2022-02-11 08:20:02 +01:00 |
|
Erik Krogh Kristensen
|
eb56a5aef3
|
support more patterns that recognize valid numbers
|
2022-02-10 19:50:35 +01:00 |
|
CodeQL CI
|
9ebbd9efa1
|
Merge pull request #7591 from asgerf/js/mysql-sinks
Approved by esbena
|
2022-02-10 12:50:36 +00:00 |
|
CodeQL CI
|
1a91a79b5b
|
Merge pull request #5841 from erik-krogh/libCode
Approved by esbena, ethanpalm
|
2022-02-10 11:36:45 +00:00 |
|
Erik Krogh Kristensen
|
d55920ad27
|
add model for the snapdragon library
|
2022-02-10 11:32:59 +01:00 |
|
Erik Krogh Kristensen
|
12d31d750a
|
convert more type-trackers to API-graphs
|
2022-02-10 09:54:52 +01:00 |
|
Stephan Brandauer
|
3e88d46e0f
|
add a getFlowLabel method to the PathNode class
|
2022-02-09 17:28:25 +01:00 |
|
Erik Krogh Kristensen
|
5340530cb7
|
use the number guard in existing queries that contained typeof checks
|
2022-02-09 09:51:57 +01:00 |
|
Erik Krogh Kristensen
|
d6721ec574
|
implement a isNaN guard for unsafe-shell-command-construction
|
2022-02-09 09:51:57 +01:00 |
|
Erik Krogh Kristensen
|
4bbb7ad320
|
Merge pull request #7876 from erik-krogh/zipRelative
JS: recognize more startswith sanitizers for path-injection queries
|
2022-02-08 15:22:39 +01:00 |
|
Erik Krogh Kristensen
|
28ba78cb76
|
add explicit this
|
2022-02-08 12:20:21 +01:00 |
|
Erik Krogh Kristensen
|
d73b2effa0
|
rename maybeGetJoinArg maybeGetPathSuffix
|
2022-02-08 10:42:06 +01:00 |
|
Erik Krogh Kristensen
|
cc3f9bf2a8
|
fix performance issue by inlining a simpler version of getASourceProp
|
2022-02-08 00:22:01 +01:00 |
|
Erik Krogh Kristensen
|
ca5f91e587
|
recognize more startswith sanitizers for path-injection queries
|
2022-02-07 14:19:13 +01:00 |
|
Erik Krogh Kristensen
|
d1d4ebb3b5
|
add values written to the global scope as exports
|
2022-02-07 13:34:18 +01:00 |
|
Erik Krogh Kristensen
|
91b03f56ad
|
move .qll files from src to lib
|
2022-02-07 13:34:18 +01:00 |
|
Erik Krogh Kristensen
|
955ad8c458
|
add JSON.stringify as a code-injection sanitizer
|
2022-02-07 13:34:18 +01:00 |
|
Erik Krogh Kristensen
|
68a5c1f5b5
|
add code-injection sink for calls to node
|
2022-02-07 13:34:18 +01:00 |
|
Erik Krogh Kristensen
|
0584a6acaf
|
recognize a nodejs re-exports in a loop
|
2022-02-07 10:12:38 +01:00 |
|
Erik Krogh Kristensen
|
ab2d3a7ca0
|
Merge pull request #7828 from Naman-ntc/main
JS: Adding model for `.get` function of `Map` in Unvalidated Dynamic Method Call
|
2022-02-04 20:19:02 +01:00 |
|
Erik Krogh Kristensen
|
edcb3ba902
|
add file sources from jszip to js/zip-slip
|
2022-02-04 14:39:49 +01:00 |
|
Naman Jain
|
aea7054938
|
modified query and added tests
|
2022-02-02 19:39:08 +05:30 |
|
Arthur Baars
|
33b97f3e0c
|
Update synchronized files
|
2022-02-02 13:30:45 +01:00 |
|
Stephan Brandauer
|
b7690e5e6b
|
Merge pull request #7734 from kaeluka/js-add-node-prefix-to-module-import
js: add support for the 'node:' prefix for importing internal modules
|
2022-01-26 10:15:08 +01:00 |
|
Erik Krogh Kristensen
|
cc527bdecd
|
Merge pull request #7721 from erik-krogh/CWE-1275
JS: add a js/samesite-none-cookie cookie
|
2022-01-25 13:28:08 +01:00 |
|
Erik Krogh Kristensen
|
caaee5e4e5
|
make a utility predicate for extracting sameSite values
|
2022-01-25 12:32:04 +01:00 |
|
Stephan Brandauer
|
9825136e58
|
add support for the 'node:' prefix for importing internal modules
|
2022-01-25 10:55:34 +01:00 |
|
Stephan Brandauer
|
35cc5ff0e2
|
Merge pull request #7715 from kaeluka/recognize-fs-extra-path-args
JS: add a predicate to recognize path arguments in calls to the fs-extra lib
|
2022-01-25 09:36:59 +01:00 |
|
CodeQL CI
|
8d1e22bc38
|
Merge pull request #7632 from erik-krogh/CWE-862
Approved by esbena, felicitymay
|
2022-01-24 12:47:16 -08:00 |
|
Erik Krogh Kristensen
|
d4bac887cf
|
add a js/samesite-none-cookie cookie
|
2022-01-24 21:39:41 +01:00 |
|