Sitelet https://web.archive.org/web/20260302235547/https://github.com/github/codeql/pull/5140
Skip to content

JS: Add taint steps for markdown parsers#5140

Merged
codeql-ci merged 8 commits intogithub:mainfrom
erik-krogh:mark
Feb 17, 2021
Merged

JS: Add taint steps for markdown parsers#5140
codeql-ci merged 8 commits intogithub:mainfrom
erik-krogh:mark

Conversation

@erik-krogh
Copy link
Contributor

@erik-krogh erik-krogh commented Feb 10, 2021 •

Adds taint-steps for markdown to HTML converters that doesn't sanitize their outputs.

Evaluation looks fine, with one new TP.

@erik-krogh erik-krogh added the Awaiting evaluation Do not merge yet, this PR is waiting for an evaluation to finish label Feb 10, 2021
erik-krogh and others added 2 commits February 11, 2021 16:16
Co-authored-by: intrigus-lgtm <60750685+intrigus-lgtm@users.noreply.github.com>
@erik-krogh erik-krogh removed the Awaiting evaluation Do not merge yet, this PR is waiting for an evaluation to finish label Feb 11, 2021
@erik-krogh erik-krogh marked this pull request as ready for review February 11, 2021 22:58
@erik-krogh erik-krogh requested a review from a team as a code owner February 11, 2021 22:58
@max-schaefer
Copy link
Contributor

OOI, I see you are using local data flow instead of API graphs. Is that due to performance reasons or ergonomics?

@erik-krogh
Copy link
Contributor Author

OOI, I see you are using local data flow instead of API graphs. Is that due to performance reasons or ergonomics?

Ergonomics.
I would have to create a bunch of API::EntryPoint to support references to global variables.

Copy link
Contributor

@asgerf asgerf left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry, this fell under my radar for a bit. LGTM, just a minor comment in the change note.

Co-authored-by: Asger F <asgerf@github.com>
@codeql-ci codeql-ci merged commit 8716cbd into github:main Feb 17, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants