mirror of
https://github.com/github/codeql.git
synced 2025-12-17 09:13:20 +01:00
915 B
915 B
2.6.1
Minor Analysis Improvements
- Data passed to the NextResponse constructor is now treated as a sink for
js/reflected-xss. - Data received from NextRequest and Request is now treated as a remote user input
source. - Added support for the
make-dirpackage. - Added support for the
openpackage. - Added taint propagation for
Uint8Array,ArrayBuffer,SharedArrayBufferandTextDecoder.decode(). - Improved detection of
WebSocketandSockJSusage. - Added data received from
WebSocketclients as a remote flow source. - Added support for additional
mkdirpmethods as sinks in path-injection queries. - Added support for additional
rimrafmethods as sinks in path-injection queries.