JS: recognize library inputs when the library exports "through" a function#7137
Merged
Conversation
a6b7777 to
b9ea4a8
Compare
esbena
reviewed
Nov 16, 2021
| result = unique( | | call.getCalleeNode().getAFunctionValue()).getAReturn() | ||
| ) | ||
| or | ||
| // the exported value is a function that returns another import. |
Contributor
There was a problem hiding this comment.
Do you know if this pattern is common in this syntactic form? If so, it would probably be worth it to support this kind of reexport directly in our import graph as well.
Contributor
Author
There was a problem hiding this comment.
I'm not sure if we can put this kind of "reexport" directly into the import graph.
At the import site it requires a user to write something like:
var lib = require("lib")(conf);So it's only "reexported" when the client calls the function.
esbena
approved these changes
Nov 16, 2021
Contributor
esbena
left a comment
There was a problem hiding this comment.
LGTM, with a suggestion for another PR.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Gets a TP/TN for CVE-2021-3820.
Here is a real example of that pattern.
Evaluation looks OK.
No change in results.