Skip to content

JS: add taint steps for fs.realpath and fs.realpathSync#958

Merged
xiemaisi merged 1 commit intomasterfrom
unknown repository
Feb 22, 2019
Merged

JS: add taint steps for fs.realpath and fs.realpathSync#958
xiemaisi merged 1 commit intomasterfrom
unknown repository

Conversation

@ghost
Copy link

@ghost ghost commented Feb 21, 2019

This change adds taint steps for fs.realpath and fs.realpathSync.

We should perhaps also whitelist these calls in js/tainted-path, this is discussed in https://jira.semmle.com/browse/ODASA-7791.

Evaluation is ongoing.

@ghost ghost added the JS label Feb 21, 2019
@ghost ghost self-requested a review as a code owner February 21, 2019 09:08
@ghost
Copy link
Author

ghost commented Feb 22, 2019

Evaluation: no changes.

@xiemaisi xiemaisi merged commit 12ed2ca into github:master Feb 22, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

Comments