Skip to content

Commit 85d7412

Browse files
committed
Add qlpack version bumps
1 parent 71bb397 commit 85d7412

File tree

840 files changed

+48576
-14
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

840 files changed

+48576
-14
lines changed

javascript/frameworks/cap/src/qlpack.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,5 +6,5 @@ suites: codeql-suites
66
extractor: javascript
77
dependencies:
88
codeql/javascript-all: "^2.6.24"
9-
advanced-security/javascript-sap-cap-all: "2.25.0"
9+
advanced-security/javascript-sap-cap-all: "2.25.1"
1010
default-suite-file: codeql-suites/javascript-code-scanning.qls
Lines changed: 38 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,38 @@
1+
/**
2+
* @name Insertion of sensitive information into log files testfile for pieces of query
3+
* @ kind problem
4+
* @problem.severity warning
5+
* @id javascript/sensitive-log-test
6+
*/
7+
8+
import javascript
9+
import advanced_security.javascript.frameworks.cap.CDS
10+
import advanced_security.javascript.frameworks.cap.CAPLogInjectionQuery
11+
12+
//annotations check
13+
// from SensitiveAnnotatedElement c
14+
// select c, ""
15+
16+
// class SensitiveExposureSource extends DataFlow::Node {
17+
// SensitiveExposureSource() {
18+
// exists(PropRead p, SensitiveAnnotatedElement c |
19+
// p.getPropertyName() = c.getEntityOrFieldName() and
20+
// this = p
21+
// )
22+
// }
23+
// }
24+
25+
//source check
26+
// from SensitiveExposureSource s
27+
// select s, ""
28+
29+
//sink check
30+
// from CdsLogSink s
31+
// select s , ""
32+
33+
from SensitiveAnnotatedElement c, string name
34+
where
35+
name = c.(CdlEntity).getName()
36+
or
37+
name = c.(CdlAttribute).getName()
38+
select c, name

javascript/frameworks/cap/test/qlpack.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,6 @@ version: 2.25.1
44
extractor: javascript
55
dependencies:
66
codeql/javascript-all: "^2.6.24"
7-
advanced-security/javascript-sap-cap-queries: "2.25.0"
8-
advanced-security/javascript-sap-cap-models: "2.25.0"
9-
advanced-security/javascript-sap-cap-all: "2.25.0"
7+
advanced-security/javascript-sap-cap-queries: "2.25.1"
8+
advanced-security/javascript-sap-cap-models: "2.25.1"
9+
advanced-security/javascript-sap-cap-all: "2.25.1"
Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
{"languages":{"javascript":{"displayName":"JavaScript/TypeScript","files":["sensitiveexposure.js","sensitive-exposure.js"],"linesOfCode":16,"name":"javascript"}}}
Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,10 @@
1+
---
2+
sourceLocationPrefix: /Users/knewbury/Desktop/GITHUB/SAP/codeql-sap-js/javascript/frameworks/cap/test/queries/sensitive-exposure
3+
baselineLinesOfCode: 16
4+
unicodeNewlines: true
5+
columnKind: utf16
6+
primaryLanguage: javascript
7+
creationMetadata:
8+
cliVersion: 2.15.5
9+
creationTime: 2024-05-09T18:26:49.738726Z
10+
finalised: true

javascript/frameworks/cap/test/queries/sensitive-exposure/sensitive-exposure/db-javascript/default/cache/.lock

Whitespace-only changes.

0 commit comments

Comments
 (0)