Skip to content

JS: add the cwd option to shell executions as a sink to js/path-injection#6533

Merged
codeql-ci merged 2 commits intogithub:mainfrom
erik-krogh:cwdPath
Aug 24, 2021
Merged

JS: add the cwd option to shell executions as a sink to js/path-injection#6533
codeql-ci merged 2 commits intogithub:mainfrom
erik-krogh:cwdPath

Conversation

@erik-krogh
Copy link
Copy Markdown
Contributor

@erik-krogh erik-krogh commented Aug 23, 2021

Recognizes the sink for CVE-2021-32662

Evaluation looks clean.

@erik-krogh erik-krogh added the Awaiting evaluation Do not merge yet, this PR is waiting for an evaluation to finish label Aug 23, 2021
@github-actions github-actions bot added the JS label Aug 23, 2021
@erik-krogh erik-krogh added the JS:changes-sources-or-sinks Changes taint sources/sinks for the JS analysis label Aug 23, 2021
@erik-krogh erik-krogh marked this pull request as ready for review August 23, 2021 13:08
@erik-krogh erik-krogh requested a review from a team as a code owner August 23, 2021 13:08
@erik-krogh erik-krogh removed the Awaiting evaluation Do not merge yet, this PR is waiting for an evaluation to finish label Aug 23, 2021
asgerf
asgerf previously approved these changes Aug 24, 2021
@asgerf
Copy link
Copy Markdown
Contributor

asgerf commented Aug 24, 2021

Actually I think adding a change note for this would be a good idea.

@codeql-ci codeql-ci merged commit c66a34b into github:main Aug 24, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation JS:changes-sources-or-sinks Changes taint sources/sinks for the JS analysis JS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants