We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 5af58d2 commit 11040d6Copy full SHA for 11040d6
ruby/ql/lib/change-notes/2024-02-12-raw-erb-output.md
@@ -0,0 +1,4 @@
1
+---
2
+category: minorAnalysis
3
4
+* Raw output ERB tags of the form `<%== ... %>` are now recognised as cross-site scripting sinks.
0 commit comments