False positive: it is valid to escape $ in javascript template string syntax
- 主要语言
- CodeQL
- 星标
- 10.1k
- 派生
- 2.1k
- 平均合并
- 2 天 15 小时
- 30 天内合并 PR
- 141
描述
**Description of the false positive**
js/useless-regexp-character-escape triggers for code like:
```javascript
const str = `hello \${name}`;
```
This is invalid, since without the backslash escape, that's a string interpolation of the `name` variable:
```javascript
const str = `hello ${name}`;
```
This triggered in the lit-html codebase on this line: https://github.com/lit/lit/blob/5eea178e0df1199cd29e9d46bc888d52882f18dd/packages/lit-html/src/lit-html.ts#L1418
Link to the code scanning issue: https://github.com/lit/lit/security/code-scanning/15
贡献指南
调研方向
Start by locating the js/useless-regexp-character-escape query and review how it handles JavaScript template strings. Use the escaped interpolation example from the issue as the reproduction case, then verify that it is no longer reported while the unescaped ${name} form remains correctly distinguished.
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- javascript
- 领域
- security
- Issue 类型
- 缺陷
- 难度
- 3/5
- 预计耗时
- 1-2 天
- 活跃度
- 停滞
- 描述清晰度
- 基本清楚
- 新手友好度
- 38/100