Files
codeql/javascript/change-notes/2020-11-09-jwt.md
Erik Krogh Kristensen 74d933d475 move change note
2020-11-11 21:09:08 +01:00

6 lines
274 B
Markdown

lgtm,codescanning
* The security queries now track taint through JWT decoding, and warns about hard-coded JWT signing keys.
Affected packages are
[jsonwebtoken](https://www.npmjs.com/package/jsonwebtoken) and
[jwt-decode](https://www.npmjs.com/package/jwt-decode)