A taint-tracking configuration for reasoning about unsafe code constructed from library input.
Import path
import semmle.javascript.security.dataflow.UnsafeCodeConstruction
Predicates
getAFeature | Gets a data flow configuration feature to add restrictions to the set of valid flow paths. |
getASelectedSinkLocation | Gets a location that will be associated with the given |
isAdditionalFlowStep | Holds if data may flow from |
isBarrier | Holds if data flow through |
isSink | Holds if |
isSource | Holds if |
observeDiffInformedIncrementalMode | Holds if sources and sinks should be filtered to only include those that may lead to a flow path with either a source or a sink in the location range given by |