Skip to content

JS: recognize modules imported by AMD imports as library inputs#8185

Merged
erik-krogh merged 1 commit into
github:mainfrom
erik-krogh:amdImp
Feb 23, 2022
Merged

JS: recognize modules imported by AMD imports as library inputs#8185
erik-krogh merged 1 commit into
github:mainfrom
erik-krogh:amdImp

Conversation

@erik-krogh

@erik-krogh erik-krogh commented Feb 23, 2022

Copy link
Copy Markdown
Contributor

Recognizes the source for CVE-2020-7792

Evaluation was uneventful.

@github-actions github-actions Bot added the JS label Feb 23, 2022
@erik-krogh erik-krogh marked this pull request as ready for review February 23, 2022 15:57
@erik-krogh erik-krogh requested a review from a team as a code owner February 23, 2022 15:57
@erik-krogh erik-krogh added the no-change-note-required This PR does not need a change note label Feb 23, 2022

@asgerf asgerf left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The change LGTM, though it does seem like that CVE ought to be flagged by js/prototype-pollution-utility which doesn't currently rely on this notion of library inputs.

@erik-krogh erik-krogh merged commit e13b2df into github:main Feb 23, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

JS no-change-note-required This PR does not need a change note

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants