Skip to content

Latest commit

 

History

History
1425 lines (1421 loc) · 118 KB

new-lgtm-alerts.md

File metadata and controls

1425 lines (1421 loc) · 118 KB

Summary

Rule ID New alerts True positives False positives
js/command-line-injection 2 2 0
js/file-access-to-http 64 5+ 0+
js/path-injection 29 3+ 2+
js/reflected-xss 5 4 1
js/regex-injection 13 4+ 1+
js/remote-property-injection 20 5+ 0+
js/user-controlled-bypass 2 0 2
js/xss 1 1 0
Total 136 24+ 6+

Details

Below, we list the new alerts organized by the project in which they were found, with links to the corresponding source locations on GitHub.

Note: Two projects, https://github.com/alejandroMonroy/curso-node-heroku and https://github.com/ninjapanda47/finders-fee-deploy, have been deleted from GitHub since we did our initial experiments and hence cannot be included. They each contained two new alerts form js/file-access-to-http, so the total number of new alerts for this rule shown below is 60 instead of the 64 mentioned in the table above.

+ js/command-line-injection (2)

+ js/command-line-injection for davros (1)

+ js/command-line-injection for new18 (1)

+ js/file-access-to-http (60)

+ js/file-access-to-http for tootspace-s3 (5)

+ js/file-access-to-http for DO080 (2)

+ js/file-access-to-http for onepage-opensource (2)

+ js/file-access-to-http for practice (3)

+ js/file-access-to-http for api-rest-example (2)

+ js/file-access-to-http for CleanOutLoudWeb (2)

+ js/file-access-to-http for local-doc (2)

+ js/file-access-to-http for CodaisseurAdvancedSession_API (2)

+ js/file-access-to-http for guodaddy (2)

+ js/file-access-to-http for trippinceylon-backend (2)

+ js/file-access-to-http for omdbclone (2)

+ js/file-access-to-http for socket-middleware (2)

+ js/file-access-to-http for document-download-prototypes (2)

+ js/file-access-to-http for myReactTemplate (2)

+ js/file-access-to-http for lipdnet (2)

+ js/file-access-to-http for Auction_Project (2)

+ js/file-access-to-http for cradle (2)

+ js/file-access-to-http for koa2-angular-mongodb (2)

+ js/file-access-to-http for light-bootstrap-dashboard (2)

+ js/file-access-to-http for bamnode (2)

+ js/file-access-to-http for felinorte (2)

+ js/file-access-to-http for Ironshop (2)

+ js/file-access-to-http for drawGuess (2)

+ js/file-access-to-http for c2s-use-current-location-prototype (2)

+ js/file-access-to-http for AroundTheWODTEST (2)

+ js/file-access-to-http for HealthCareSystem (2)

+ js/file-access-to-http for pay-link-set-up (2)

+ js/file-access-to-http for Node-Angular (2)

+ js/path-injection (29)

+ js/path-injection for server-examples (1)

+ js/path-injection for ungit (2)

+ js/path-injection for chrome (1)

+ js/path-injection for DockerSecurityPlayground (9)

+ js/path-injection for HEAD (1)

+ js/path-injection for mock-node (2)

+ js/path-injection for mediacenterjs (2)

+ js/path-injection for expressCart (1)

+ js/path-injection for cgm-remote-monitor (1)

+ js/path-injection for urllib (1)

+ js/path-injection for manager (2)

+ js/path-injection for yaktime (1)

+ js/path-injection for juttle (3)

+ js/path-injection for manager (1)

+ js/reflected-xss (5)

+ js/reflected-xss for ampersand (2)

+ js/reflected-xss for atom-elmjutsu (1)

+ js/reflected-xss for manager (1)

+ js/reflected-xss for isomorphic-tutorial (1)

+ js/regex-injection (13)

+ js/regex-injection for ftd-web (1)

+ js/regex-injection for HEAD (3)

+ js/regex-injection for goof (1)

+ js/regex-injection for react-pwa-reference (1)

+ js/regex-injection for angularjs-periscope (3)

+ js/regex-injection for conduit (1)

+ js/regex-injection for intern (1)

+ js/regex-injection for webdrivercss-adminpanel (1)

+ js/regex-injection for traceur-compiler (1)

+ js/remote-property-injection (20)

+ js/remote-property-injection for hud-disaster-data (3)

+ js/remote-property-injection for communityservice (2)

+ js/remote-property-injection for new-website (2)

+ js/remote-property-injection for old-website (1)

+ js/remote-property-injection for iloveopensource (1)

+ js/remote-property-injection for scrapoxy (1)

+ js/remote-property-injection for lightning (1)

+ js/remote-property-injection for orcinus (1)

+ js/remote-property-injection for ophan-sparklines (2)

+ js/remote-property-injection for balmung (4)

+ js/remote-property-injection for pump.io (1)

+ js/remote-property-injection for ql.io (1)

+ js/user-controlled-bypass (2)

+ js/user-controlled-bypass for firebase-tools (1)

+ js/user-controlled-bypass for verdaccio (1)

+ js/xss (1)

+ js/xss for nodewiki (1)