False positive: it is valid to escape $ in javascript template string syntax
未關閉
false-positive
- 主要語言
- CodeQL
- 星號
- 10.1k
- 分支
- 2.1k
- 平均合併
- 2 天 15 小時
- 30 天內合併 PR
- 141
描述
**Description of the false positive**
js/useless-regexp-character-escape triggers for code like:
```javascript
const str = `hello \${name}`;
```
This is invalid, since without the backslash escape, that's a string interpolation of the `name` variable:
```javascript
const str = `hello ${name}`;
```
This triggered in the lit-html codebase on this line: https://github.com/lit/lit/blob/5eea178e0df1199cd29e9d46bc888d52882f18dd/packages/lit-html/src/lit-html.ts#L1418
Link to the code scanning issue: https://github.com/lit/lit/security/code-scanning/15
貢獻指南
評估
這個 Issue 還沒有評估資料。