mirror of
https://github.com/github/codeql.git
synced 2026-01-30 06:42:57 +01:00
In future we could try harder to find out whether you're Fprintf'ing to stdout, a file named xyz.log etc, but for now this causes Fprintf'ing to an HTTP writer to be mistaken for log-injection rather than just XSS.