- The
js/incomplete-sanitizationquery now also checks regular expressions constructed usingnew RegExp(..). Previously it only checked regular expression literals. - Regular expression-based sanitisers implemented with
new RegExp(..)are now detected in more cases. - Regular expression related queries now account for unknown flags.
- Added taint-steps for
String.prototype.toWellFormed. - Added taint-steps for
Map.groupByandObject.groupBy. - Added taint-steps for
Array.prototype.findLast. - Added taint-steps for
Array.prototype.findLastIndex.