Skip to content

UnderscoreJS output escaping improvement? #345

@GaryJones

Description

@GaryJones

The Underscorejs output escaping sniff checks for <%=, but it's possible that <%= _.escape(...) would also sufficiently escape the output.

I don't know UnderscoreJS, so this needs looking into, but it may help remove some false positives.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions