forked from NodeSecure/js-x-ray
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
- Loading branch information
Showing
40 changed files
with
2,508 additions
and
5,074 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,9 +1,14 @@ | ||
# Editor configuration, see https://editorconfig.org | ||
root = true | ||
|
||
[*] | ||
indent_size = 4 | ||
indent_style = space | ||
end_of_line = lf | ||
charset = utf-8 | ||
trim_trailing_whitespace = true | ||
indent_style = space | ||
indent_size = 2 | ||
insert_final_newline = true | ||
trim_trailing_whitespace = true | ||
end_of_line = lf | ||
|
||
[*.md] | ||
max_line_length = off | ||
trim_trailing_whitespace = false |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,4 +1,3 @@ | ||
test/fixtures | ||
test/utils | ||
cases/ | ||
temp.js |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,7 +1,7 @@ | ||
{ | ||
"extends": "@slimio/eslint-config", | ||
"rules": { | ||
"jsdoc/require-jsdoc": "off", | ||
"lines-between-class-members": "off" | ||
"extends": "@nodesecure/eslint-config", | ||
"parserOptions": { | ||
"sourceType": "module", | ||
"requireConfigFile": false | ||
} | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file was deleted.
Oops, something went wrong.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,61 +1,56 @@ | ||
"use strict"; | ||
|
||
// Require Third-party Dependencies | ||
const { walk } = require("estree-walker"); | ||
const meriyah = require("meriyah"); | ||
|
||
// Require Internal Dependencies | ||
const Analysis = require("./src/Analysis"); | ||
|
||
function runASTAnalysis(str, options = Object.create(null)) { | ||
const { module = true, isMinified = false } = options; | ||
|
||
// Note: if the file start with a shebang then we remove it because 'parseScript' may fail to parse it. | ||
// Example: #!/usr/bin/env node | ||
const strToAnalyze = str.charAt(0) === "#" ? str.slice(str.indexOf("\n")) : str; | ||
const { body } = meriyah.parseScript(strToAnalyze, { | ||
next: true, loc: true, raw: true, module: Boolean(module) | ||
}); | ||
|
||
const sastAnalysis = new Analysis(); | ||
|
||
// we walk each AST Nodes, this is a purely synchronous I/O | ||
walk(body, { | ||
enter(node) { | ||
// Skip the root of the AST. | ||
if (Array.isArray(node)) { | ||
return; | ||
} | ||
|
||
const action = sastAnalysis.walk(node); | ||
if (action === "skip") { | ||
this.skip(); | ||
} | ||
} | ||
}); | ||
|
||
const dependencies = sastAnalysis.dependencies; | ||
const { idsLengthAvg, stringScore, warnings } = sastAnalysis.getResult(isMinified); | ||
const isOneLineRequire = body.length <= 1 && dependencies.size <= 1; | ||
|
||
return { | ||
dependencies, warnings, idsLengthAvg, stringScore, isOneLineRequire | ||
}; | ||
// Import Third-party Dependencies | ||
import { walk } from "estree-walker"; | ||
import * as meriyah from "meriyah"; | ||
|
||
// Import Internal Dependencies | ||
import Analysis from "./src/Analysis.js"; | ||
|
||
export function runASTAnalysis(str, options = Object.create(null)) { | ||
const { module = true, isMinified = false } = options; | ||
|
||
// Note: if the file start with a shebang then we remove it because 'parseScript' may fail to parse it. | ||
// Example: #!/usr/bin/env node | ||
const strToAnalyze = str.charAt(0) === "#" ? str.slice(str.indexOf("\n")) : str; | ||
const { body } = meriyah.parseScript(strToAnalyze, { | ||
next: true, loc: true, raw: true, module: Boolean(module) | ||
}); | ||
|
||
const sastAnalysis = new Analysis(); | ||
|
||
// we walk each AST Nodes, this is a purely synchronous I/O | ||
walk(body, { | ||
enter(node) { | ||
// Skip the root of the AST. | ||
if (Array.isArray(node)) { | ||
return; | ||
} | ||
|
||
const action = sastAnalysis.walk(node); | ||
if (action === "skip") { | ||
this.skip(); | ||
} | ||
} | ||
}); | ||
|
||
const dependencies = sastAnalysis.dependencies; | ||
const { idsLengthAvg, stringScore, warnings } = sastAnalysis.getResult(isMinified); | ||
const isOneLineRequire = body.length <= 1 && dependencies.size <= 1; | ||
|
||
return { | ||
dependencies, warnings, idsLengthAvg, stringScore, isOneLineRequire | ||
}; | ||
} | ||
|
||
module.exports = { | ||
runASTAnalysis, | ||
CONSTANTS: { | ||
Warnings: Object.freeze({ | ||
parsingError: "ast-error", | ||
unsafeImport: "unsafe-import", | ||
unsafeRegex: "unsafe-regex", | ||
unsafeStmt: "unsafe-stmt", | ||
unsafeAssign: "unsafe-assign", | ||
encodedLiteral: "encoded-literal", | ||
shortIdentifiers: "short-identifiers", | ||
suspiciousLiteral: "suspicious-literal", | ||
obfuscatedCode: "obfuscated-code" | ||
}) | ||
} | ||
export const CONSTANTS = { | ||
Warnings: Object.freeze({ | ||
parsingError: "ast-error", | ||
unsafeImport: "unsafe-import", | ||
unsafeRegex: "unsafe-regex", | ||
unsafeStmt: "unsafe-stmt", | ||
unsafeAssign: "unsafe-assign", | ||
encodedLiteral: "encoded-literal", | ||
shortIdentifiers: "short-identifiers", | ||
suspiciousLiteral: "suspicious-literal", | ||
obfuscatedCode: "obfuscated-code" | ||
}) | ||
}; |
This file was deleted.
Oops, something went wrong.
Oops, something went wrong.