Skip to content

Commit ad60aff

Browse files
committed
Update which sink kinds are shared between languages
1 parent fdd1e3f commit ad60aff

File tree

1 file changed

+4
-3
lines changed

1 file changed

+4
-3
lines changed

shared/mad/codeql/mad/ModelValidation.qll

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -29,16 +29,17 @@ module KindValidation<KindValidationConfigSig Config> {
2929
[
3030
// shared
3131
"code-injection", "command-injection", "environment-injection", "file-content-store",
32-
"html-injection", "js-injection", "ldap-injection", "log-injection", "path-injection",
33-
"request-forgery", "sql-injection", "url-redirection", "xpath-injection",
32+
"html-injection", "js-injection", "ldap-injection", "log-injection", "nosql-injection",
33+
"path-injection", "request-forgery", "sql-injection", "url-redirection",
34+
"xpath-injection", "unsafe-deserialization",
3435
// Java-only currently, but may be shared in the future
3536
"bean-validation", "fragment-injection", "groovy-injection", "hostname-verification",
3637
"information-leak", "intent-redirection", "jexl-injection", "jndi-injection",
3738
"mvel-injection", "notification", "ognl-injection", "pending-intents",
3839
"response-splitting", "trust-boundary-violation", "template-injection", "url-forward",
3940
"xslt-injection",
4041
// JavaScript-only currently, but may be shared in the future
41-
"mongodb.sink", "nosql-injection", "unsafe-deserialization",
42+
"mongodb.sink",
4243
// Swift-only currently, but may be shared in the future
4344
"database-store", "format-string", "hash-iteration-count", "predicate-injection",
4445
"preferences-store", "tls-protocol-version", "transmission", "webview-fetch", "xxe",

0 commit comments

Comments
 (0)