CodeQL library for JavaScript/TypeScript
codeql/javascript-all 2.3.1-dev (changelog, source)
Search

Module CodeInjectionQuery

Provides a taint-tracking configuration for reasoning about code injection vulnerabilities.

Note, for performance reasons: only import this file if CodeInjection::Configuration is needed, otherwise CodeInjectionCustomizations should be imported instead.

Import path

import semmle.javascript.security.dataflow.CodeInjectionQuery

Imports

CodeInjection
javascript

Provides classes for working with JavaScript programs, as well as JSON, YAML and HTML.

Classes

Configuration

DEPRRECATED. Use the CodeInjectionFlow module instead.

Modules

CodeInjectionConfig

A taint-tracking configuration for reasoning about code injection vulnerabilities.

Aliases

CodeInjectionFlow

Taint-tracking for reasoning about code injection vulnerabilities.