github / github/codeql

False positive: it is valid to escape $ in javascript template string syntax

未关闭
#15,077 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
false-positive
主要语言
CodeQL
星标
10.1k
派生
2.1k
平均合并
2 天 15 小时
30 天内合并 PR
141

描述

**Description of the false positive**

js/useless-regexp-character-escape triggers for code like:

```javascript
const str = `hello \${name}`;
```

This is invalid, since without the backslash escape, that's a string interpolation of the `name` variable:

```javascript
const str = `hello ${name}`;
```

This triggered in the lit-html codebase on this line: https://github.com/lit/lit/blob/5eea178e0df1199cd29e9d46bc888d52882f18dd/packages/lit-html/src/lit-html.ts#L1418

Link to the code scanning issue: https://github.com/lit/lit/security/code-scanning/15

贡献指南

打开贡献指南

调研方向

Start by locating the js/useless-regexp-character-escape query and review how it handles JavaScript template strings. Use the escaped interpolation example from the issue as the reproduction case, then verify that it is no longer reported while the unescaped ${name} form remains correctly distinguished.

由索引模型根据 Issue 内容生成。

评估

技术栈
javascript
领域
security
Issue 类型
缺陷
难度
3/5
预计耗时
1-2 天
活跃度
停滞
描述清晰度
基本清楚
新手友好度
38/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。