Skip to content

JS: also consider relative exports when finding library inputs#12189

Merged
erik-krogh merged 2 commits into
github:mainfrom
erik-krogh:more-export
Feb 27, 2023
Merged

JS: also consider relative exports when finding library inputs#12189
erik-krogh merged 2 commits into
github:mainfrom
erik-krogh:more-export

Conversation

@erik-krogh
Copy link
Copy Markdown
Contributor

@erik-krogh erik-krogh commented Feb 14, 2023

CVE-2022-36036: TP

And simplify some of the related code.
I just had to change an existing test slightly to test the new behavior.

Evaluation was unevenful.

@github-actions github-actions Bot added the JS label Feb 14, 2023
Comment thread javascript/ql/lib/semmle/javascript/NPM.qll Fixed
@erik-krogh erik-krogh marked this pull request as ready for review February 15, 2023 09:45
@erik-krogh erik-krogh requested a review from a team as a code owner February 15, 2023 09:45
@erik-krogh erik-krogh added the no-change-note-required This PR does not need a change note label Feb 15, 2023
@calumgrant calumgrant requested a review from hmac February 20, 2023 09:37
@erik-krogh erik-krogh merged commit 4ffe20a into github:main Feb 27, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

JS no-change-note-required This PR does not need a change note

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants