File tree Expand file tree Collapse file tree 3 files changed +9
-1
lines changed
src/queries/security/CWE-730 Expand file tree Collapse file tree 3 files changed +9
-1
lines changed Original file line number Diff line number Diff line change @@ -21,7 +21,7 @@ private import codeql.rust.security.regex.RegexInjectionExtensions
2121 * A taint configuration for detecting regular expression injection vulnerabilities.
2222 */
2323module RegexInjectionConfig implements DataFlow:: ConfigSig {
24- predicate isSource ( DataFlow:: Node source ) { source instanceof ThreatModelSource }
24+ predicate isSource ( DataFlow:: Node source ) { source instanceof ActiveThreatModelSource }
2525
2626 predicate isSink ( DataFlow:: Node sink ) { sink instanceof RegexInjectionSink }
2727
Original file line number Diff line number Diff line change 1+ extensions :
2+ - addsTo :
3+ pack : codeql/threat-models
4+ extensible : threatModelConfiguration
5+ data :
6+ - ["local", true, 0]
Original file line number Diff line number Diff line change @@ -6,3 +6,5 @@ dependencies:
66extractor : rust
77tests : .
88warnOnImplicitThis : true
9+ dataExtensions :
10+ - default-threat-models.model.yml
You can’t perform that action at this time.
0 commit comments