Skip to content

JS: Declassify sensitive exprs with special characters#2987

Merged
asgerf merged 2 commits into
github:masterfrom
asger-semmle:js/urls-not-sensitive-data
Mar 9, 2020
Merged

JS: Declassify sensitive exprs with special characters#2987
asgerf merged 2 commits into
github:masterfrom
asger-semmle:js/urls-not-sensitive-data

Conversation

@asgerf

@asgerf asgerf commented Mar 4, 2020

Copy link
Copy Markdown
Contributor

Fixes this FP

@asgerf asgerf added the JS label Mar 4, 2020
@asgerf asgerf requested a review from a team as a code owner March 4, 2020 17:10

@esbena esbena left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Perhaps add a change note like this:

| Use of password hash with insufficient computational effort (`js/insufficient-password-hash`) | Fewer false positive results | This query now recognizes additional cases that do not require secure hashing. |

@asgerf asgerf force-pushed the js/urls-not-sensitive-data branch from 89aa584 to a3779dc Compare March 5, 2020 14:48
esbena
esbena previously approved these changes Mar 5, 2020
@asgerf asgerf force-pushed the js/urls-not-sensitive-data branch from a3779dc to a9a9c14 Compare March 7, 2020 15:15
@asgerf

asgerf commented Mar 9, 2020

Copy link
Copy Markdown
Contributor Author

@erik-krogh can I get an approval from you since Esben is away?

@erik-krogh erik-krogh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

@asgerf asgerf merged commit 5a1bf94 into github:master Mar 9, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants