Skip to content

append: Remove error for use of append in VIP Go#439

Merged
rebeccahum merged 1 commit intodevelopfrom
fix/remove-error-for-append
Aug 19, 2019
Merged

append: Remove error for use of append in VIP Go#439
rebeccahum merged 1 commit intodevelopfrom
fix/remove-error-for-append

Conversation

@GaryJones
Copy link
Contributor

It's not clear why this violation is marked as an Error for VIP Go ruleset, when none of the other HTMLExecutingFunctions are left as their default of Warnings.

Since the best the Sniff can do is provide warnings when a variable is used (though that variable may already be safe, and not contain user input), then it would seem odd to change just one function call to an Error for VIP Go.

It's not clear why this violation is marked as an Error for VIP Go ruleset, when none of the other HTMLExecutingFunctions are left as their default of Warnings.

Since the best the Sniff can do is provide warnings when a variable is used (though that variable may already be safe, and not contain user input), then it would seem odd to change just one function call to an Error for VIP Go.
@GaryJones GaryJones added this to the 2.1 milestone Aug 18, 2019
@GaryJones GaryJones requested a review from rebeccahum August 18, 2019 13:46
@GaryJones GaryJones self-assigned this Aug 18, 2019
@rebeccahum rebeccahum merged commit b3e134c into develop Aug 19, 2019
@rebeccahum rebeccahum deleted the fix/remove-error-for-append branch August 19, 2019 14:06
@GaryJones GaryJones modified the milestones: 2.1, 2.0.1 Jul 3, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants