CodeQL library for JavaScript/TypeScript
codeql/javascript-all 2.6.23 (changelog, source)
Search

Predicate DynamicCreation::isCreateScriptNodeWoIntegrityCheck

Holds if createCall creates a <script ../> element which never has its integrity attribute set locally.

Import path

import semmle.javascript.security.FunctionalityFromUntrustedSource
predicate isCreateScriptNodeWoIntegrityCheck(CallNode createCall)