False positive in javascript.express.security.audit.xss.direct-response-write.direct-response-write #3381
Closed
1 of 3 tasks
Labels
bug
Something isn't working
Describe the bug
This alert should not trigger on non-rendered response types, like JSON.
To Reproduce
Run Semgrep on an express endpoint with:
Expected behavior
No Semgrep finding
Priority
How important is this to you?
The text was updated successfully, but these errors were encountered: