Skip to content

Releases: SonarSource/SonarJS

7.0.1

08 Dec 18:52
Compare
Choose a tag to compare

Revert custom rule API removal

7.0.0

04 Dec 15:58
273b54b
Compare
Choose a tag to compare

All rules rely on TypeScript parser.

6.7.0.14237

12 Nov 14:16
61aa15d
Compare
Choose a tag to compare
Update rule metadata (#2346)

6.6.0.13923

22 Oct 13:55
27505f0
Compare
Choose a tag to compare

Many new rules related to cryptography (see MMF-1894 ) and many rules migrated to ESLint parser

6.5.0.13383

28 Sep 07:59
5718261
Compare
Choose a tag to compare
Update rule metadata (#2175)

SonarJS 6.2.2

23 Sep 12:59
Compare
Choose a tag to compare

Bugfix release:

  • Fix potential security vulnerability where eslint-bridge component opens http server on all local interface (0.0.0.0) (SSF-122)

SonarJS 6.4.1

25 Aug 16:21
f53e6e4
Compare
Choose a tag to compare

Bugfix release:

  • Filtering out huge files is now applied only to JS/TS.

SonarJS 6.4

24 Aug 11:14
Compare
Choose a tag to compare

New rules:

  • S2598: File uploads should be restricted (formidable)
  • S4502: Disabling CSRF protection is security-sensitive
  • S4507: Delivering code in production with debug features activated is security-sensitive
  • S5689: Recovering fingerprints from web application technologies should not be possible
  • S5691: Statically serving hidden files is security-sensitive
  • S5693: Allowing requests with excessive content length is security-sensitive

Improved rules:

  • S5122: now raised only when permissive CORS policy is obvious; Support for cors middleware.

Deprecated rules:

Changes in the requirements:

  • The plugin now requires Node.js 10
  • The plugin no longer relies on user-provided TypeScript: TypeScript is now shipped with the analyzer.
  • Support for solution-style tsconfigs
  • Very large files are now excluded from analysis by default (property sonar.javascript.maxFileSize controls the threshold)

6.3.0.12464

10 Jul 12:53
7e7a586
Compare
Choose a tag to compare

Hardening and bugfixes

Analyzer for JavaScript/TypeScript 6.2.1

03 Apr 12:35
3444def
Compare
Choose a tag to compare

Fix bug in SonarLint when analyzing JS file before TS file (#1680)