Draft: Remove eslint object injection rule
What does this MR do?
Removes the ESLint detect-object-injection
rule from the default Semgrep ruleset, which has a high FP rate. The disabled rule was moved to rules_disabled/eslint.yml
to allow users to re-enable the rule if desired.
This implements option 1 discussed here.
What are the relevant issue numbers?
Does this MR meet the acceptance criteria?
-
Changelog entry added -
Documentation created/updated for GitLab EE, if necessary -
Documentation created/updated for this project, if necessary -
Documentation reviewed by technical writer or follow-up review issue created -
Tests added for this feature/bug -
Job definition updated, if necessary -
Conforms to the code review guidelines -
Conforms to the Go guidelines -
Security reports checked/validated by reviewer
Edited by James Liu