Files
codeql/benjamin-button.md
Esben Sparre Andreasen cc08eccf05 Remove additional Xss sinks
2022-01-05 19:46:05 +00:00

2.5 KiB

benjamin-buttons.md

This file describes the changes that have been applied to the library to make it behave as if it was younger.

TaintedPath.ql

Sinks added between 2020-01-01 and 2020-10-06 have been removed. Found by looking at:

Sinks added between 2018-08-02 and 2020-01-01 have been removed. Found by looking at:

Sinks from the "graceful-fs" and "fs-extra" (added before the open-sourcing squash).

Xss.ql

Sinks added between 2020-01-01 and 2020-10-06 have been removed. Found by looking at:

SqlInjection.ql

Sinks added between 2020-01-01 and 2020-10-06 have been removed. Found by looking at:

Sinks added between 2018-08-02 and 2020-01-01 have been removed. Found by looking at:

TypeTracking in SQL.qll (added before the open-sourcing squash)

The model of mssql and sequelize (added before the open-sourcing squash)

PseudoProperties

Pseudo-properties ($name$) used in type-tracking and global dataflow configurations have been disabled. Found by searching for "\$.*\$".