add change note

This commit is contained in:
Erik Krogh Kristensen
2021-02-25 16:03:58 +01:00
parent 214aa072b9
commit af7a188bbd

View File

@@ -0,0 +1,4 @@
lgtm,codescanning
* Sources of user input and sinks for `js/request-forgery` in the http-proxy are now recognized.
Affected packages are
[http-proxy](https://www.npmjs.com/package/http-proxy)