Block or Report
Block or report asgerf
Report abuse
Contact GitHub support about this user’s behavior. Learn more about reporting abuse.
Report abusePopular repositories
-
-
dts-tree-sitter Public
Generate TypeScript .d.ts files for using tree-sitter grammars.
-
-
864 contributions in the last year
Less
More
Contribution activity
May 2023
Created 36 commits in 1 repository
Created a pull request in github/codeql that received 6 comments
JS: Add sources and sinks related to GitHub Actions
Adds sources and sinks based on this PR from @R3x with comments from @JarLob. This PR is essentially a port of that PR with the following differences:
+220
−0
•
6
comments
Opened 7 other pull requests in 1 repository
github/codeql
3
open
4
merged
- Ruby: two bug fixes
- JS: Be more conservative about flagging "search" call arguments as regex
- Ruby: fix some name clashes between summarized callables
- JS: Avoid using global vars in documentation examples
- JS: remove mention of TrackedNode from docs
- JS: Fix broken message in example query
- Ruby: add SQL injection sinks to meta query
Reviewed 15 pull requests in 1 repository
github/codeql
15 pull requests
- ReDoS: revert new superlinear algorithm.
-
Ruby: Include both
selfparameters and SSA definitions in call graph construction -
Ruby: Include underlying SSA parameter definition in
localFlowSsaParamCaptureInput - Ruby: Allow for flow out of callbacks passed to summarized methods in type tracking
- JS: require arguments to be shell interpreted to be flagged by indirect-command-injection
- Ruby: Allow for flow through callbacks to summarized methods in type tracking
- JS: update MaD sink kinds
-
Ruby: Include
selfparameters in type tracking flow-through logic - JS/Ruby/QL/Python: sync dbscheme fragments
-
JS: fixup in the qhelp for
js/prototype-polluting-assignment - JS: Add more sources, more unit tests, fixes to the GitHub Actions injection query
- JavaScript: Use gender-neutral language in qhelp for js/user-controlled-bypass
- JS: Add pragma[only_bind_out] to Locatable::toString() calls
- JS: Allow NonKeyCiphers to include truncated SHA-512 MDs in Forge JS libr…
- JS: Add a few more DOM element sources




