mirror of
https://github.com/github/codeql.git
synced 2026-04-28 02:05:14 +02:00
add the resolve library as a sink to js/path-injection
This commit is contained in:
4
javascript/change-notes/2021-06-04-resolve.md
Normal file
4
javascript/change-notes/2021-06-04-resolve.md
Normal file
@@ -0,0 +1,4 @@
|
||||
lgtm,codescanning
|
||||
* Paths used with the [resolve](https://npmjs.com/package/resolve) command are seen as sinks for the `js/path-injection` query.
|
||||
Affected packages are
|
||||
[resolve](https://npmjs.com/package/resolve)
|
||||
Reference in New Issue
Block a user