Skip to content

Commit 5781b51

Browse files
author
Esben Sparre Andreasen
committed
JS: change notes for js/stored-xss
1 parent 33f98dd commit 5781b51

File tree

1 file changed

+7
-3
lines changed

1 file changed

+7
-3
lines changed

change-notes/1.19/analysis-javascript.md

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -4,11 +4,15 @@
44

55
* Modelling of taint flow through array operations has been improved. This may give additional results for the security queries.
66

7+
* Support for popular libraries has been improved. Consequently, queries may produce more results on code bases that use the following features:
8+
- file system access, for example through [fs-extra](https://github.com/jprichardson/node-fs-extra) or [globby](https://www.npmjs.com/package/globby)
9+
10+
711
## New queries
812

9-
| **Query** | **Tags** | **Purpose** |
10-
|-----------------------------|-----------|--------------------------------------------------------------------|
11-
| *@name of query (Query ID)* | *Tags* |*Aim of the new query and whether it is enabled by default or not* |
13+
| **Query** | **Tags** | **Purpose** |
14+
|-----------------------------------------------|------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
15+
| Stored cross-site scripting (`js/stored-xss`) | security, external/cwe/cwe-079, external/cwe/cwe-116 | Highlights uncontrolled stored values flowing into HTML content, indicating a violation of [CWE-079](https://cwe.mitre.org/data/definitions/79.html). Results shown on lgtm by default. |
1216

1317
## Changes to existing queries
1418

0 commit comments

Comments
 (0)