codeql/python/change-notes/2021-11-16-posixpath.md

261 B

lgtm,codescanning

  • Added modeling of the posixpath, ntpath, and genericpath modules for path operations (although these are not supposed to be used), resulting in new sinks for the Uncontrolled data used in path expression (py/path-injection) query.