JS: recognize strings in callbacks in getAReplacementString #5400
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Gets a TP/TN for CVE-2021-3377
I decided to use
StringReplaceCall::replaces/2
insidegetAReplacementString
because it gives me a natural way of getting the TP for the CVE, and I couldn't come up with a good reason for why not to do it (no test-case broke, and evaluation is clean).Evaluation is good.
No change in performance or results.