Skip to content

Commit 051133e

Browse files
committed
minor updates
1 parent 119a6bc commit 051133e

45 files changed

Lines changed: 10 additions & 1748 deletions

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

README.md

Lines changed: 10 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -6,16 +6,22 @@ We identified a total of 716 dangerous data flows in extensions.
66

77
We verified 21 extension vulnerabilities with PoC exploits for code injection, impacting more than **6 million installations**.
88

9-
Eextension developers and GitHub were notified of our results.
9+
Extension developers and GitHub were notified of our results.
10+
11+
## Research paper for our work
12+
13+
Our paper has been accepted and will appear at the Network and Distributed System Security Symposium (NDSS).
1014

1115
## What is in this repo?
1216

1317
This is a modified copy of the [vscode-codeql-starter repository](https://github.com/github/vscode-codeql-starter/).
1418

1519
The repo includes
16-
- Example queries to identify sources and sinks, visit [source-and-sink](./codeql-custom-queries-javascript/source-and-sink/)
17-
- A set of CodeQL rules for identifying VS Code extension vulnerabilities, visit [dataflow](./codeql-custom-queries-javascript/dataflow/).
18-
For more on how the dataflow queries work, visit [dataflow docs](./codeql-custom-queries-javascript/dataflow/README.md)
20+
- Example queries to identify sources and sinks, visit [queries/source-and-sink](./queries/source-and-sink/)
21+
- A set of CodeQL rules for identifying VS Code extension vulnerabilities, visit [queries/dataflow](./queries/dataflow/).
22+
For more on how the dataflow queries work, visit [dataflow docs](./queries/dataflow/README.md)
23+
- sample CodeQL databases at [sample-data](./sample-data/) to test the queries on
24+
- The [ql](./ql) folder contains libraries in order for the CodeQL queries to function properly
1925

2026

2127
## Requirements

codeql-custom-queries-javascript/codeql-pack.lock.yml

Lines changed: 0 additions & 4 deletions
This file was deleted.

codeql-custom-queries-javascript/dataflow/README.md

Lines changed: 0 additions & 25 deletions
This file was deleted.

codeql-custom-queries-javascript/dataflow/config-to-eval.ql

Lines changed: 0 additions & 40 deletions
This file was deleted.

codeql-custom-queries-javascript/dataflow/config-to-fileWrite.ql

Lines changed: 0 additions & 39 deletions
This file was deleted.

codeql-custom-queries-javascript/dataflow/config-to-shell.ql

Lines changed: 0 additions & 39 deletions
This file was deleted.

codeql-custom-queries-javascript/dataflow/fileRead-to-eval.ql

Lines changed: 0 additions & 54 deletions
This file was deleted.

codeql-custom-queries-javascript/dataflow/fileRead-to-fileWrite.ql

Lines changed: 0 additions & 54 deletions
This file was deleted.

codeql-custom-queries-javascript/dataflow/fileRead-to-shell.ql

Lines changed: 0 additions & 54 deletions
This file was deleted.

codeql-custom-queries-javascript/dataflow/filter-file-write/README.md

Lines changed: 0 additions & 5 deletions
This file was deleted.

0 commit comments

Comments
 (0)