Skip to content

Detects "RegExp(variable)", which might allow an attacker to DOS your server with a long-running regular expression (security/detect-non-literal-regexp)

⚠️ This rule warns in the ✅ recommended config.

More information: Regular Expression DoS and Node.js

Released under the Apache License 2.0.