Skip to content

Comments

fix: detect-non-literal-regexp-314#197

Open
Rajesh-Sangepu wants to merge 1 commit intodependency-check:mainfrom
Rajesh-Sangepu:fix/semgrep-detect-non-literal-regexp-314-kW9RwFlTkx
Open

fix: detect-non-literal-regexp-314#197
Rajesh-Sangepu wants to merge 1 commit intodependency-check:mainfrom
Rajesh-Sangepu:fix/semgrep-detect-non-literal-regexp-314-kW9RwFlTkx

Conversation

@Rajesh-Sangepu
Copy link

This PR addresses a Semgrep SAST finding related to dynamic RegExp construction.
The argument name is now properly escaped before being used in the regex.
This prevents potential ReDoS risks caused by regex metacharacters.
Existing masking logic and behavior remain unchanged.
The fix is minimal and aligned with secure coding best practices.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant