eslint-community/eslint-plugin-security

A more relevant "detect-object-injection"

Open

#21 ouverte le 30 août 2017

Voir sur GitHub
 (20 commentaires) (12 réactions) (0 assignés)JavaScript (131 forks)batch import
help wanted

Métriques du dépôt

Stars
 (2 074 stars)
Métriques de merge PR
 (Merge moyen 2j 18h) (4 PRs mergées en 30 j)

Description

Is there any way that we can work towards a more helpful/relevant report of Object injection sinks?

I can't think of a relevant security use case where Object injection would be relevant outside of the scope of a function directly linked to a web service.

I can understand based on tree traversal that determining the difference in between functions that are used in response to direct network calls would be [near] impossible to determine, but if I use bracket notation at the top level of my module, likely this rule should not notify.

Guide contributeur