Skip to main content
interlace
Plugin: mongodb-security

Changelog

Release history and version updates for eslint-plugin-mongodb-security

Live from GitHub

This changelog is fetched directly from CHANGELOG.md on GitHub and cached for 2 hours.

Live changelogfrom eslint-plugin-mongodb-security/CHANGELOG.md, cached for 2 hours.Edit on GitHub

[8.3.0] - 2026-02-08

8.3.2

Patch Changes

  • #364 86baa02 Thanks @ofri-peretz! - Add the ecosystem and oxlint marks to the README logo row. Each plugin now leads with Interlace -> its ecosystem (node, nestjs, express, react, mongodb, postgresql, mysql, sqlite, prisma, drizzle, knex, typeorm, sequelize, lambda, vercel, jwt) -> oxlint -> ESLint; the generic quality plugins carry the row without an ecosystem mark. README-only change - no rule behaviour is affected. The patch bump is what carries the new README onto npm, which only refreshes a package README on publish.

8.3.1

Patch Changes

  • #338 dc25c81 Thanks @ofri-peretz! - Re-publish every package so npm carries the optimised artifact

    No source changed. This is a no-op patch whose entire purpose is to ship the artifact the current build already produces.

    Manifests. scripts and devDependencies are now stripped from every published package.json. Neither can do anything in a consumer’s node_modules — npm never runs one and never installs the other — but they shipped in all 27 manifests, cluttered the npm page, and were read by SCA tools scanning installed manifests. No package declares a lifecycle hook, so nothing observable changes. Every published package is bumped so this applies uniformly rather than to a subset.

    Tarballs. 20 packages were last published before the build pipeline changed and still ship AGENTS.md, CHANGELOG.md, JSDoc in the emitted .js, and the full generated .d.ts tree:

    packagepublishedrebuiltsaving
    eslint-plugin-react-features547 kB320 kB−227 kB
    eslint-plugin-secure-coding653 kB477 kB−176 kB
    eslint-plugin-conventions241 kB116 kB−125 kB
    eslint-plugin-browser-security380 kB291 kB−89 kB
    eslint-plugin-maintainability178 kB116 kB−62 kB
    eslint-plugin-react-a11y232 kB173 kB−59 kB
    eslint-plugin-reliability148 kB90 kB−58 kB
    eslint-plugin-vercel-ai-security187 kB130 kB−57 kB
    eslint-plugin-operability90 kB43 kB−47 kB
    eslint-plugin-jwt140 kB95 kB−45 kB
    eslint-plugin-modularity98 kB58 kB−40 kB
    eslint-plugin-nestjs-security122 kB86 kB−36 kB
    eslint-plugin-sqlite-security54 kB20 kB−34 kB
    eslint-plugin-sequelize-security54 kB21 kB−34 kB
    eslint-plugin-prisma-security52 kB19 kB−33 kB
    eslint-plugin-mysql-security52 kB19 kB−33 kB
    eslint-plugin-typeorm-security52 kB19 kB−33 kB
    eslint-plugin-drizzle-security52 kB19 kB−33 kB
    eslint-plugin-knex-security51 kB19 kB−32 kB
    eslint-plugin-modernization45 kB38 kB−7 kB

    Those 20 go from 3428 kB to 2169 kB — −36.7%. The remaining 7 were released after the pipeline change and only gain the manifest strip.

    A new check in scripts/check-published-artifacts.ts fails the build if scripts or devDependencies ever reappear in a published manifest, so the strip cannot silently regress.

    The dependency ranges did not need updating: every plugin pins @interlace/eslint-devkit with a caret that 1.6.0 satisfies, verified by a clean install of an unchanged plugin resolving devkit 1.6.0 with zero dependencies and no typescript in the tree.

  • Updated dependencies [dc25c81]:

    • @interlace/eslint-devkit@1.6.1

8.3.0

Minor Changes

  • #328 0231140 Thanks @ofri-peretz! - Eliminate the false-positive storm on real MongoDB/Mongoose codebases.

    A dry run against mikemajesty/nestjs-microservice-boilerplate-api (393★, NestJS 11 + Mongoose, 253 files) produced 145 findings under recommended, 138 of which were false positives. Method names alone were doing all the work: find is also Array.prototype.find, connect is also a Redis client and a TypeORM query runner, and findOne/updateOne are the vocabulary of every generic repository wrapper ever written.

    RuleBeforeAfter
    no-select-sensitive-fields800
    no-unbounded-find418
    no-bypass-middleware116
    require-auth-mechanism70
    require-tls-connection20
    total14518

    The remaining 18 are all real Mongoose model calls in one repository file.

    New shared utils/receiver.ts answers, once per file, whether a call's receiver is plausibly MongoDB — a PascalCase model identifier, a model/collection/db name, a db.collection(...) chain, or a value bound to a mongodb/mongoose import. Connection rules are stricter still: client/connection earn no benefit of the doubt, since they are just as likely Redis or Postgres.

    no-select-sensitive-fields additionally requires evidence that a sensitive field exists before claiming one is exposed — either the query names it (.select('password'), { projection: { password: 1 } }) or a sensitive field name is visible in the file. The new requireVisibleSensitiveField option (default true) restores the old behaviour for codebases whose schemas live outside the files that query them.

    allowInTests now recognises test/, tests/, __tests__/, __mocks__/, e2e/ and fixtures/ directories, not only a *.test.ts suffix — a testcontainers helper is not a production connection.

    Every fix ships a regression fixture taken from the real scan alongside a true-positive test, so no rule goes inert.

Patch Changes

8.2.8

Patch Changes

  • #294 659f6dc Thanks @ofri-peretz! - Rewrite description and keywords on every published package for npm search discovery. npm ranks on name, description, and keywords, and the registry only picks up these fields at publish — so this is metadata-only and takes effect for each package on its next release.

    Descriptions now lead with the search phrase. Every one starts ESLint plugin for <the thing you'd search> instead of a brand-first or category-first framing, and names the concrete vulnerabilities the plugin actually detects. Three were corrected while doing so:

    • eslint-plugin-import-next claimed "100x faster no-cycle detection". No 100x measurement exists: CLAIMS.md records 3.1x end-to-end (8x in pure rule execution) on a 5,483-file React codebase, and the highest number in any benchmark result is 54.9x on the synthetic corpus. The description now states the real-codebase figure.
    • eslint-plugin-secure-coding claimed SQL injection, XSS and CSRF coverage — none of which are its rules. It now names what it does detect: LDAP, XPath, XXE, GraphQL and template injection, unsafe deserialization, ReDoS, missing authentication, and PII in logs.
    • eslint-plugin-secure-coding ("89 rules") and eslint-plugin-react-a11y ("37 rules") hard-coded rule counts that had drifted from reality. Counts are generated into interlace-numbers.json; hand-typed copies are removed rather than corrected.

    Keywords now match the vocabulary of the plugins that rank. eslint-plugin-security, eslint-plugin-jsx-a11y, eslint-plugin-n and eslint-plugin-import all carry the eslint / eslintplugin / eslint-plugin trio — six of our packages were missing eslintplugin, and every one now carries all three plus static-analysis, linting and code-quality. Security plugins add sast, appsec and vulnerability; node-security and secure-coding also carry nodesecurity, the exact keyword eslint-plugin-security ranks on. Each plugin gained the CWE identifiers and attack names for what it detects (cwe-78 command injection, cwe-22 path traversal, cwe-89 SQL injection, cwe-79 XSS, cwe-347 JWT algorithm confusion, cwe-352 CSRF, cwe-943 NoSQL injection), and node-security gained the crypto vocabulary it had been missing entirely despite absorbing the crypto rule set (crypto, cryptography, weak-hash, md5, sha1, timing-attack).

    No rule behavior, exports, or configuration changes.

  • Updated dependencies [e1cdf83, 659f6dc]:

    • @interlace/eslint-devkit@1.4.3

8.2.7

Patch Changes

  • #274 acdd2ad Thanks @ofri-peretz! - Widen optional peer ranges to accept mongoose ^9 and mongodb driver ^7. The rules lint call patterns statically and never import either library, and the interface-compatibility suite passes against mongoose 9.7 / mongodb 7.5 — the old caps just broke npm install in current-major repos.

8.2.6

Patch Changes

  • #269 7028fe2 Thanks @ofri-peretz! - docs: dual-logo README header (Interlace mark + ESLint mark side by side) and closing Interlace footer — refreshes the README rendered on npmjs.com. No runtime changes.

  • Updated dependencies [7028fe2]:

    • @interlace/eslint-devkit@1.4.2

8.2.5

Patch Changes

  • #252 d67e395 Thanks @ofri-peretz! - Fix Codecov badge showing "unknown" — switch from flag to component URL format

8.2.4

Patch Changes

  • #143 213cde1 Thanks @ofri-peretz! - fix(no-missing-null-checks): eliminate 53 false positives via three new narrowing patterns

    Rules that were recognized as null guards are now correctly identified as safe:

    1. Truthy if guardif (obj) { obj.prop } — direct truthy check proves non-null. Also covers chains: if (response) protects response.data.items.
    2. Short-circuit ANDobj && obj.prop — right side of && only runs when left is truthy.
    3. Ternary consequentobj ? obj.prop : fallback — truthy test guards the consequent.

    Also: bumped beforeAll timeout to 30 seconds in 7 compatibility test files (__compatibility__/*.spec.ts). Native-addon packages routinely exceed the previous 10-second default on a cold ESM load.

  • Updated dependencies [736a5fe]:

    • @interlace/eslint-devkit@1.4.1

Added

  • no-hardcoded-connection-string: Detect hardcoded mongodb:// and mongodb+srv:// URIs in string and template literals (CWE-798, CVSS 7.5)
  • no-hardcoded-credentials: Flag user, username, pass, password, auth properties with literal string values (CWE-798, CVSS 7.5)
  • no-debug-mode-production: Detect mongoose.set('debug', true) calls exposing query details (CWE-489, CVSS 3.1)
  • no-unsafe-where: Detect $where operator in object literals and .where('$where') method calls — RCE vector (CWE-943, CVSS 9.0)
  • no-operator-injection: Flag dangerous MongoDB operators ($ne, $gt, $lt, etc.) when values reference user input (CWE-943, CVSS 9.1)
  • no-unbounded-find: Require .limit() on find()/findOne() queries to prevent resource exhaustion (CWE-400, CVSS 4.3)
  • require-tls-connection: Require tls: true or ssl: true in connect()/createConnection() options (CWE-295, CVSS 7.4)
  • no-bypass-middleware: Flag Mongoose methods that bypass pre/post middleware hooks (updateOne, deleteMany, insertMany, bulkWrite, etc.) (CWE-284, CVSS 5.3)
  • Comprehensive test suites for all 8 rules (163 total tests)
  • Test coverage improved from 72.61% to 91.30% lines

[8.2.3] - 2026-02-08

Bug Fixes

  • align codecov component IDs with full package names (2831b968)

Documentation

  • fix changelog header format across all packages (c3a15082)

❤️ Thank You

  • Ofri Peretz

[8.2.2] - 2026-02-06

Bug Fixes

  • align codecov component names and update docs components (0a59a86c)

❤️ Thank You

  • Ofri Peretz

[8.2.1] - 2026-02-02

This was a version bump only for eslint-plugin-mongodb-security to align it with other projects, there were no code changes.

Changelog

All notable changes to eslint-plugin-mongodb-security will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

[1.0.0] - 2026-01-09

Added

  • Initial release with 16 security rules
  • NoSQL Injection Prevention (4 rules)
    • no-unsafe-query - Prevents string concatenation in MongoDB queries
    • no-operator-injection - Prevents $ne, $gt, $lt injection attacks
    • no-unsafe-where - Prevents $where operator RCE (CVE-2025-23061, CVE-2024-53900)
    • no-unsafe-regex-query - Prevents ReDoS via $regex
  • Credentials & Connection Security (4 rules)
    • no-hardcoded-connection-string - Prevents credentials in connection URIs
    • no-hardcoded-credentials - Prevents hardcoded auth options
    • require-tls-connection - Requires TLS for production connections
    • require-auth-mechanism - Requires explicit SCRAM-SHA-256
  • Mongoose ODM Security (5 rules)
    • require-schema-validation - Requires Mongoose schema validators
    • no-select-sensitive-fields - Prevents returning password/token fields
    • no-bypass-middleware - Prevents bypassing pre/post hooks
    • no-unsafe-populate - Prevents user-controlled populate()
    • require-lean-queries - Suggests .lean() for read-only queries
  • Best Practices (3 rules)
    • no-unbounded-find - Requires limit() on find queries
    • require-projection - Requires field projection
    • no-debug-mode-production - Prevents debug mode in production
  • Full support for mongodb, mongoose, mongodb-client-encryption, @typegoose/typegoose
  • AI-optimized error messages with CWE and OWASP references
  • Three configuration presets: recommended, strict, mongoose
  • OWASP Top 10 2021 mapping (A01-A07 coverage)

View on GitHub →

Building secure JavaScript with Interlace? Star the repo to get new rules and CWE coverage as we ship them — or follow the AI-code-security benchmarks behind them.

On this page

No Headings