Changelog
Release history and version updates for eslint-plugin-secure-coding
Live from GitHub
This changelog is fetched directly from CHANGELOG.md on GitHub and cached for 2 hours.
3.3.1
Patch Changes
-
#213
391dbe6Thanks @ofri-peretz! - Align every security rule'smeta.docs.cvssto the CVSS its finding actually emits. The emitted machine-readable message sources itsCVSS:xfromCWE_MAPPINGviaformatLLMMessage→enrichFromCWE, but the staticmeta.docs.cvssdocumentation field had drifted on 45 rules across these 7 plugins — e.g.no-hardcoded-credentialsdocumented9.5while emittingCVSS:9.8(the value the published article and SARIF/LLM consumers already read).This corrects the documentation metadata only — no emitted finding changes. Locked by
security-cvss-docs-consistency.lock.test.ts(cross-plugin: every security rule'smeta.docs.cvssmust equal the CVSS it emits), theno-hardcoded-credentialsrule lock (real ESLintLinteremission), and a devkitenrichFromCWEcontract test pinningCWE-798 → 9.8.Follow-up (not in scope): 50 security rules document a CVSS that never appears in any emitted message (their messages carry no CWE), and several rules emit the generic CWE score where a rule-specific score may be warranted — both change emitted output and are separate decisions.
3.3.0
Minor Changes
-
#170
4cbf3edThanks @ofri-peretz! - Addrecommended-strictpreset + quick-start in READMENew preset:
configs['recommended-strict']Same 16-rule set asrecommendedbut every rule promoted to'error'. For teams that want CI to block on all security findings, not just critical ones. The recommended preset stays unchanged.// eslint.config.mjs import securePlugin from 'eslint-plugin-secure-coding'; export default [...securePlugin.configs['recommended-strict']];README: copy-paste quick-start block Added a one-line usage example immediately after
npm installso adopters don't have to discover the preset table buried further down the page. Also added cross-plugin discovery links tonode-security,jwt, andexpress-securityfor teams that want broader coverage.
Patch Changes
-
#137
a56da52Thanks @ofri-peretz! - fix(detect-object-injection): suppress ~3,470 Edge false positives via four new safe-pattern guards- Test-file skip: rule is now silent on
*.test.*,*.spec.*,__tests__/, and*.fixture.*paths for...inloop variable: keys fromfor (const key in obj)are own property names, not user inputObject.keys/entriesiteration:for (const key of Object.keys(obj))is safe by construction- Typed-array objects (
new Float32Array/Uint8Array/Int32Array/…): element access is numeric, not string-keyed
None of the guards widen the TP surface — dangerous properties (
__proto__,constructor,prototype) and genuine user-input bracket access still fire. Closes the largest single source of ILB-Wild noise. - Test-file skip: rule is now silent on
-
#144
8843ce7Thanks @ofri-peretz! - fix: ILB-Wild FP reduction + doc examples + doc-test-alignment scanner fixesno-unlimited-resource-allocation— FP reduction (430 Edge FPs)- Skip loop-allocation reporting when the first argument is a numeric literal (e.g.
Buffer.alloc(1024)inside a loop is statically bounded, not a risk) - Skip
Array.isArray,Array.from,Array.ofcalls in thealloc/Arraypattern check (these don't allocate unbounded memory)
no-hardcoded-credentials— FP reduction (~280 Edge FPs)- Extended test-file skip to cover
.fixture.,.mock.,__mocks__/,/tests/,/fixtures/,/mocks/paths - Skip string literals that are fallback values in
process.env.X || 'fallback'expressions — the secret lives in the environment, the string is only a dev-mode default
Doc examples — 4 rules now have ❌ Incorrect examples
lambda-security/no-missing-authorization-checklambda-security/no-overly-permissive-iam-policynode-security/prefer-native-crypto(renamed non-standard### ❌ Third-Party (Flagged)to### ❌ Incorrect)vercel-ai-security/require-tool-confirmation(replaced placeholder with a real tested example)
ilb-doc-test-alignmentscanner fixes- Accept both
## ❌and### ❌headings (docs use H3 under an H2## Examplessection; was only finding H2) - Slice from end-of-line rather than end-of-regex-match (prevents
## ❌ Incorrect Codefrom leaving a partial heading in the parsed section)
Result:
ilb:doc-test-alignment→ 206 ok, 0 doc has no ❌ examples (was 165 missing). - Skip loop-allocation reporting when the first argument is a numeric literal (e.g.
-
#141
38ab670Thanks @ofri-peretz! - fix: remove falsemeta.fixable: 'code'declarations from 21 rules that had nofix()functionRules that declared
fixable: 'code'in their ESLint meta without an actualfix()implementation would show the ⚡ auto-fix icon in editors and CI formatters but apply no change when--fixwas run. This patch removes the misleading declaration from:browser-security/no-clickjackingimport-next/first,named,no-barrel-import,no-import-module-exports,no-namespacenode-security/no-buffer-overread,no-unsafe-dynamic-require,no-zip-slipreact-features/react-no-inline-functionsreliability/no-jsdoc-terminator-in-example(usessuggest, not auto-fix; corrected tohasSuggestions: trueonly)secure-coding/no-directive-injection,no-electron-security-issues,no-graphql-injection,no-improper-sanitization,no-improper-type-validation,no-ldap-injection,no-unchecked-loop-condition,no-unlimited-resource-allocation,no-weak-password-recovery,no-xpath-injection
-
#148
82718c2Thanks @ofri-peretz! - feat+fix: ILB-Wild FP reduction + two new quality rulesno-unsafe-deserializationFP reduction (~112 FPs)- Track
fs.readFileSync('literal')calls inliteralPathFileVars— a file read with a hardcoded path (bundled config) is not user-controlled input for safe deserializers (JSON.parse, schema-validating parsers).eval()still fires even on literal-path reads.
no-buffer-overreadFP reduction (~129 FPs)- Remove
b(single-char, too broad) andchunk(too common for array chunks) from the Buffer alias heuristic —isBufferTypenow only matchesbufandbytesby name, reducing false matches on non-Buffer variables.
New rule:
modernization/prefer-template-literal- Flags
"string " + variableconcatenation and suggests the equivalent template literal. - Auto-fix produces the correct
`string ${variable}`replacement. - Pure string literal chains (
"a" + "b") and numeric addition are not flagged. - Closes P2 quality FN
prob_string_concatin the ILB-Arena-Quality bench.
New rule:
modularity/no-mutable-exports- Flags
export letandexport var— module exports should be immutableconstbindings so all importers share a stable reference. - Auto-fix replaces
let/varwithconst. - Closes P2 quality FN
prob_mutable_exportin the ILB-Arena-Quality bench.
- Track
-
Updated dependencies [
736a5fe]:- @interlace/eslint-devkit@1.4.1
3.2.0 (Unreleased)
Added
- New
./oxlintsub-export for use with oxlint's JS plugin API. Wire it via{ "jsPlugins": ["eslint-plugin-secure-coding/oxlint"] }in.oxlintrc.json. Exposes the same rule set as the main entry; rules degrade gracefully when type information is unavailable (oxlint's JS plugin context does not provideparserServices). The default ESLint entry (./) is unchanged.
3.1.3 (2026-02-09)
This was a version bump only for eslint-plugin-secure-coding to align it with other projects, there were no code changes.
Changelog
All notable changes to this project will be documented in this file.
The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
[3.1.1] - 2026-02-09
This was a version bump only for eslint-plugin-secure-coding to align it with other projects, there were no code changes.
[3.1.0] - 2026-02-09
This was a version bump only for eslint-plugin-secure-coding to align it with other projects, there were no code changes.
[3.0.3] - 2026-02-09
This was a version bump only for eslint-plugin-secure-coding to align it with other projects, there were no code changes.
[3.0.2] - 2025-12-20
Performance
- detect-object-injection: Replaced
getText()+ regex with AST-based validation (~4x faster) - detect-non-literal-fs-filename: Replaced
getText()+ regex with AST-based validation - no-timing-attack: Set-based O(1) lookups for sensitive variables and auth patterns
- no-buffer-overread: Set-based O(1) lookups for buffer methods and user-controlled keywords
- no-missing-csrf-protection: Set-based O(1) lookups for protected HTTP methods
- detect-child-process: Set-based O(1) lookups for dangerous child_process methods
[3.0.1] - 2025-12-20
Fixed444
- detect-object-injection: Reduced false positives by detecting validation patterns:
includes()checks in enclosing if-blockshasOwnProperty()/Object.hasOwn()/inoperator checks- Preceding guard clauses with early exit (
if (!valid) throw) - Numeric index access (
items[0],items[1]) now recognized as safe
- detect-non-literal-fs-filename: Allow safe path patterns:
path.join(__dirname, ...literals)with all literal arguments- Paths validated with
startsWith()checks (both inside if-blocks and after guard clauses)
- no-timing-attack: Skip false positives in timing-safe contexts:
- Length comparisons before
crypto.timingSafeEqual() - Early returns inside functions using
timingSafeEqual - Fixed file-level sensitive variable detection to be function-scoped
- Length comparisons before
- no-unsanitized-html: Track sanitized variables:
- Variables assigned from
DOMPurify.sanitize()now recognized as safe
- Variables assigned from
- no-unlimited-resource-allocation: Allow safe static paths:
fs.readFileSync(path.join(__dirname, ...literals))patterns now recognized as safe
[3.0.0] - 2025-12-14
Added
- OWASP Mobile Top 10 Coverage: Added 40 new rules targeting mobile security risks (M1-M10).
- New Presets:
owasp-mobile-top-10: Comprehensive mobile security ruleset.
- Documentation:
- Full "Mobile Security" table in README with CVSS scores and fixable icons.
- Updated
AGENTS.mdwith complete rule catalog for AI assistants.
Changed
- Recommended Config: Now includes critical mobile security rules for hybrid web/mobile apps.
- Rule Improvements: Refined AST detection for
no-clickjackingandno-unvalidated-deeplinksto reduce false positives.
[1.0.0] - 2025-01-01
Added
- Initial release with 48 security-focused ESLint rules
- LLM-optimized error messages with CWE references and OWASP mapping
- Three preset configurations:
recommended,strict,owasp-top-10 - Full ESLint 9 flat config support
- TypeScript support
Security Rules
Injection Prevention (11 rules)
no-sql-injection- SQL injection preventiondatabase-injection- Comprehensive SQL/NoSQL/ORM injectiondetect-eval-with-expression- Dynamic eval() detectiondetect-child-process- Command injection detectionno-unsafe-dynamic-require- Dynamic require() preventionno-graphql-injection- GraphQL injection preventionno-xxe-injection- XXE injection preventionno-xpath-injection- XPath injection preventionno-ldap-injection- LDAP injection preventionno-directive-injection- Template injection preventionno-format-string-injection- Format string injection prevention
Path & File Security (3 rules)
detect-non-literal-fs-filename- Path traversal detectionno-zip-slip- Zip slip vulnerability preventionno-toctou-vulnerability- TOCTOU race condition detection
Regex Security (3 rules)
detect-non-literal-regexp- ReDoS detection in RegExpno-redos-vulnerable-regex- ReDoS pattern detectionno-unsafe-regex-construction- Unsafe regex prevention
Object & Prototype (2 rules)
detect-object-injection- Prototype pollution detectionno-unsafe-deserialization- Unsafe deserialization prevention
Cryptography (6 rules)
no-hardcoded-credentials- Hardcoded secrets detectionno-weak-crypto- Weak algorithm detectionno-insufficient-random- Weak randomness detectionno-timing-attack- Timing attack preventionno-insecure-comparison- Insecure comparison detectionno-insecure-jwt- JWT security issues detection
Input Validation & XSS (5 rules)
no-unvalidated-user-input- Input validation enforcementno-unsanitized-html- XSS via innerHTML preventionno-unescaped-url-parameter- URL parameter XSS preventionno-improper-sanitization- Output encoding enforcementno-improper-type-validation- Type confusion prevention
Authentication & Authorization (3 rules)
no-missing-authentication- Auth check enforcementno-privilege-escalation- Privilege escalation detectionno-weak-password-recovery- Secure password reset enforcement
Session & Cookies (3 rules)
no-insecure-cookie-settings- Cookie security enforcementno-missing-csrf-protection- CSRF protection enforcementno-document-cookie- Direct cookie access detection
Network & Headers (5 rules)
no-missing-cors-check- CORS validation enforcementno-missing-security-headers- Security header enforcementno-insecure-redirects- Open redirect preventionno-unencrypted-transmission- HTTPS enforcementno-clickjacking- Clickjacking prevention
Data Exposure (2 rules)
no-exposed-sensitive-data- Data exposure preventionno-sensitive-data-exposure- Log sanitization enforcement
Buffer & Memory (1 rule)
no-buffer-overread- Buffer safety enforcement
DoS & Resource (2 rules)
no-unlimited-resource-allocation- Resource limit enforcementno-unchecked-loop-condition- Infinite loop prevention
Platform-Specific (2 rules)
no-electron-security-issues- Electron security enforcementno-insufficient-postmessage-validation- postMessage validation
View on GitHub →
Building secure JavaScript with Interlace? Star the repo to get new rules and CWE coverage as we ship them — or follow the AI-code-security benchmarks behind them.