- The
@security-severitymetadata ofcs/log-forginghas been reduced from 7.8 (high) to 6.1 (medium). - The
@security-severitymetadata ofcs/web/xsshas been increased from 6.1 (medium) to 7.8 (high).
- The
cs/constant-conditionquery has been simplified. The query no longer reports trivially constant conditions as they were found to generally be intentional. As a result, it should now produce fewer false positives. Additionally, the simplification means that it now reports all the results thatcs/constant-comparisonused to report, and as consequence, that query has been deleted.