Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

JS: Add support for threat models #17256

Merged
merged 22 commits into from
Nov 4, 2024

Merge branch 'main' into js-threat-models

c0ad9ba
Select commit
Loading
Failed to load commit list.
Merged

JS: Add support for threat models #17256

Merge branch 'main' into js-threat-models
c0ad9ba
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / CodeQL failed Nov 1, 2024 in 7s

5 configurations not found

Warning: Code scanning may not have found all the alerts introduced by this pull request, because 5 configurations present on refs/heads/main were not found:

Actions workflow (rust-analysis.yml)

  • ❓  .github/workflows/rust-analysis.yml:analyze/language:rust

Actions workflow (csv-coverage-metrics.yml)

  • ❓  .github/workflows/csv-coverage-metrics.yml:publish-csharp
  • ❓  .github/workflows/csv-coverage-metrics.yml:publish-java

Actions workflow (codeql-analysis.yml)

  • ❓  .github/workflows/codeql-analysis.yml:CodeQL-Build

Actions workflow (cpp-swift-analysis.yml)

  • ❓  .github/workflows/cpp-swift-analysis.yml:CodeQL-Build

New alerts in code changed by this pull request

  • 2 errors

See annotations below for details.

View all branch alerts.

Annotations

Check failure on line 39 in javascript/ql/lib/semmle/javascript/Concepts.qll

See this annotation in the file changed.

Code scanning / CodeQL

Bidirectional imports for abstract classes Error

This abstract class doesn't import its subclass
RemoteFlowPassword
but imports 56 other subclasses, such as
GitHubActionsContextSource
.
This abstract class doesn't import its subclass
RemoteServerResponse
but imports 56 other subclasses, such as
GitHubActionsContextSource
.
This abstract class doesn't import its subclass
RemoteFlowSourceFromDBAccess
but imports 56 other subclasses, such as
GitHubActionsContextSource
.

Check failure on line 14 in javascript/ql/lib/semmle/javascript/security/dataflow/RemoteFlowSources.qll

See this annotation in the file changed.

Code scanning / CodeQL

Bidirectional imports for abstract classes Error

This abstract class doesn't import its subclass
RemoteFlowPassword
but imports 50 other subclasses, such as
GitHubActionsContextSource
.
This abstract class doesn't import its subclass
RemoteServerResponse
but imports 50 other subclasses, such as
GitHubActionsContextSource
.
This abstract class doesn't import its subclass
RemoteFlowSourceFromDBAccess
but imports 50 other subclasses, such as
GitHubActionsContextSource
.