Performance and precision pass (#64)

This commit is contained in:
Eli Peter 2026-05-04 19:58:04 -04:00 committed by GitHub
parent c7c5e0f3a1
commit fb698d2c27
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
97 changed files with 9932 additions and 517 deletions

View file

@ -301,6 +301,9 @@ fn positive_python() {
// py.sqli.text_format must fire on the SQLAlchemy text() shape.
"py.sqli.execute_format",
"py.sqli.text_format",
// CVE-2023-6568 (mlflow) reflected XSS via make_response f-string;
// also catches the `+`-concat shape in xss_reflected.py.
"py.xss.make_response_format",
],
);
}