javascript-bambuddy.qls 602 B

12345678910111213141516
  1. # Bambuddy JavaScript Security & Quality Suite
  2. #
  3. # Extends the standard javascript-security-and-quality suite,
  4. # excluding false positives documented below.
  5. - description: "Bambuddy JavaScript security and quality"
  6. - import: codeql-suites/javascript-security-and-quality.qls
  7. from: codeql/javascript-queries
  8. # XSS through DOM (2): False positives —
  9. # 1. coverage/sorter.js: generated Istanbul coverage report, not our code
  10. # 2. TimelapseEditorModal.tsx: URL.createObjectURL(file) creates a safe
  11. # blob: URL used as <audio src>, not HTML content injection
  12. - exclude:
  13. id: js/xss-through-dom