eslint-community/eslint-plugin-security

A more relevant "detect-object-injection"

開放

#21 建立於 2017年8月30日

 (20 則留言) (12 個反應) (0 位負責人)JavaScript (131 個分叉)batch import
help wanted

倉庫指標

星標
 (2,074 顆星)
PR 合併指標
 (平均合併 2天 18小時) (30 天內合併 4 個 PR)

描述

Is there any way that we can work towards a more helpful/relevant report of Object injection sinks?

I can't think of a relevant security use case where Object injection would be relevant outside of the scope of a function directly linked to a web service.

I can understand based on tree traversal that determining the difference in between functions that are used in response to direct network calls would be [near] impossible to determine, but if I use bracket notation at the top level of my module, likely this rule should not notify.

貢獻者指南