False positive: it is valid to escape $ in javascript template string syntax
Open
false-positive
- Dominant language
- CodeQL
- Stars
- 10.1k
- Forks
- 2.1k
- Avg merge
- 2d 15h
- Merged PRs (30d)
- 141
Description
**Description of the false positive**
js/useless-regexp-character-escape triggers for code like:
```javascript
const str = `hello \${name}`;
```
This is invalid, since without the backslash escape, that's a string interpolation of the `name` variable:
```javascript
const str = `hello ${name}`;
```
This triggered in the lit-html codebase on this line: https://github.com/lit/lit/blob/5eea178e0df1199cd29e9d46bc888d52882f18dd/packages/lit-html/src/lit-html.ts#L1418
Link to the code scanning issue: https://github.com/lit/lit/security/code-scanning/15
Contributor guide
Assessment
This issue has not been assessed yet.