mirror of
https://github.com/github/codeql.git
synced 2025-12-19 10:23:15 +01:00
295 B
295 B
lgtm,codescanning
- The query "Cross-site scripting" (
java/xss) has been improved to report fewer false positives by removing thejavax.servlet.http.HttpServletResponse.sendErrorsink since Servlet API implementations generally already escape the error message, preventing script injection.