Skip to content

Commit f737054

Browse files
authored
Merge pull request github#13380 from asgerf/js/fix-sink-kind
JS: Fix invalid source kind in test
2 parents 182513a + 5aea6fc commit f737054

File tree

13 files changed

+25
-31
lines changed

13 files changed

+25
-31
lines changed

javascript/ql/test/library-tests/DataExtensions/Test.expected

Lines changed: 0 additions & 7 deletions
This file was deleted.

javascript/ql/test/library-tests/DataExtensions/Test.ql

Lines changed: 0 additions & 11 deletions
This file was deleted.
Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,2 @@
1+
| connection.example.ts:4:20:4:20 | q |
2+
| connection.example.ts:9:18:9:18 | q |
Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,4 @@
1+
import javascript
2+
private import semmle.javascript.security.dataflow.SqlInjectionCustomizations
3+
4+
query predicate sqlInjectionSinks(DataFlow::Node node) { node instanceof SqlInjection::Sink }
Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
| execa.example.js:2:7:2:9 | cmd |
Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/javascript-all
4+
extensible: sinkModel
5+
data:
6+
- ["@example/execa", "Member[shell].Argument[0]", "command-injection"]

javascript/ql/test/library-tests/DataExtensions/execa.model.yml

Lines changed: 0 additions & 10 deletions
This file was deleted.
Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
import javascript
2+
private import semmle.javascript.security.dataflow.CommandInjectionCustomizations
3+
4+
query predicate commandInjectionSinks(DataFlow::Node node) {
5+
node instanceof CommandInjection::Sink
6+
}
Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,2 @@
1+
| message.example.js:1:46:1:50 | event |
2+
| message.example.js:2:16:2:25 | event.data |

0 commit comments

Comments
 (0)