-
Notifications
You must be signed in to change notification settings - Fork 1.9k
JS: Modeling of fs-extra functions
#19143
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
5c13997 to
e45edc5
Compare
e45edc5 to
769fe75
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Pull Request Overview
This pull request introduces modeling for previously missing fs-extra functions in our security queries.
- Adds additional fs-extra functions as sinks in HTTP-to-file and file-to-HTTP security tests.
- Expands test coverage for CWE-912, CWE-200, and CWE-022 cases using various fs and fs-extra methods.
- Updates change notes to document the new fs-extra method support.
Reviewed Changes
Copilot reviewed 4 out of 8 changed files in this pull request and generated 3 comments.
| File | Description |
|---|---|
| javascript/ql/test/query-tests/Security/CWE-912/HttpToFileAccess.js | Integrates new fs-extra functions (open, writev, writevSync) in HTTP-based file access tests. |
| javascript/ql/test/query-tests/Security/CWE-200/FileAccessToHttp.js | Adds file operations using readvSync and readv to simulate file access leading to HTTP alerts. |
| javascript/ql/test/query-tests/Security/CWE-022/TaintedPath/more-fs-extra.js | Models a variety of fs-extra methods as potential sinks in tainted path scenarios. |
| javascript/ql/lib/change-notes/2025-03-28-fs-extra.md | Documents the introduction of additional fs-extra method support. |
Files not reviewed (4)
- javascript/ql/lib/semmle/javascript/frameworks/NodeJSLib.qll: Language not supported
- javascript/ql/test/query-tests/Security/CWE-022/TaintedPath/TaintedPath.expected: Language not supported
- javascript/ql/test/query-tests/Security/CWE-200/FileAccessToHttp.expected: Language not supported
- javascript/ql/test/query-tests/Security/CWE-912/HttpToFileAccess.expected: Language not supported
Tip: Copilot code review supports C#, Go, Java, JavaScript, Markdown, Python, Ruby and TypeScript, with more languages coming soon. Learn more
The following pull request introduces modeling for previously missing
fs-extrafunctions.