Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CSP 'script-src' directive is violated by lodash/template #101

Open
dimovpetar opened this issue Aug 11, 2021 · 0 comments
Open

CSP 'script-src' directive is violated by lodash/template #101

dimovpetar opened this issue Aug 11, 2021 · 0 comments

Comments

@dimovpetar
Copy link

Hello,

The built xqlint.js file contains big part of lodash. The function lodash.template is not compliant with CSP Level 2, as it performs dynamic code execution. Since it's not used at all, removing it is the best option.
More information about Unsafe eval expessions and lodash.template .
This reflects on the ace editor ajaxorg/ace#4506.

Best regards,
Petar

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant