Content Pack Version - CP.9.2.0.17055 (JavaScript)

Each Ruleset Content Pack includes improvements to queries, and optionally, also to presets. Technically, these changes are delivered through database upgrade scripts which affect the relevant tables.

As with any CxSAST product release, the Content Pack resets the Checkmarx built-in presets to the default query set.

This Content Pack uses a unified installer and it includes all the Content Packs published for version 9.2.0. It includes updates to JavaScript.

Installation order

  • This is a cumulative Content Pack, it can be installed over any of the version 9.2.0 Content Packs and does not require other Content Packs.

  • This Content Pack requires 9.2.0 Hotfix 19 or higher previously installed on the CxSAST Environment (Manager and Engines).

It includes all the changes provided by Content Pack 15 and the following improvements:

  • in JavaScript language:

Added the following queries:

  • JavaScript_Medium_Threat/Client_Privacy_Violation - Improved the Angular support related to outputs

  • JavaScript_Hight_Risk/Client_DOM_XSS - Corrected report of Angular results when $event is involved

  • JavaScript_Angular/Angular_Client_DOM_XSS and Angular_Client_Stored_DOM_XSS - removed Angular Mustache interpolation from XSS Outputs

Version Upgrade
It is mandatory to install at least the same Content Pack number for newer versions while upgrading.
This step ensures the accuracy of the results is maintained while upgrading.

 

Which CxSAST version is this Content Pack for?
As stated in the release notes, this Content Pack is only compatible with CxSAST v9.2.0.

Which languages were targeted in this Content Pack?
This Content Pack provides improvements for JavaScript

Can this Content Pack be installed on top of other Content Packs?
Yes, this Content Pack is a multi-language Content Pack. It inherits all the characteristics of previous Content Packs, i.e, it is cumulative.

Does this Content Pack depend on other Content Packs?
No, there are no dependencies on other Content Packs. All Content Packs are cumulative, meaning that when one Content Pack is installed it includes all the previous Content Packs.

Can this Content Pack be installed over other Content Packs?
Yes it can. It will override its content.

Is there any order of installation between this Content Pack and Content Pack 15?
Yes. But there is no need to install other Content Packs. This Content Pack includes all the previous.

Can this Content Pack be installed in other versions, like CxSAST 9.0?
No. Versions 9.0 and 9.3 will not have a Content Pack 17 available.

Does this Content Pack depend on any HotFix?
Yes, This Content Pack requires HotFix 19.