Skip to content

feat(probes): add prototype pollution detection for __proto__ usage#512

Open
7amed3li wants to merge 7 commits intoNodeSecure:masterfrom
7amed3li:feat/prototype-pollution-detection
Open

feat(probes): add prototype pollution detection for __proto__ usage#512
7amed3li wants to merge 7 commits intoNodeSecure:masterfrom
7amed3li:feat/prototype-pollution-detection

Conversation

@7amed3li
Copy link
Contributor

@7amed3li 7amed3li commented Feb 2, 2026

Adds a probe to detect potential prototype pollution via __proto__ usage.

Closes #487

@changeset-bot
Copy link

changeset-bot bot commented Feb 2, 2026

🦋 Changeset detected

Latest commit: 65b47c3

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@nodesecure/js-x-ray Minor

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@7amed3li 7amed3li force-pushed the feat/prototype-pollution-detection branch from 403ea1d to 5f0be02 Compare February 2, 2026 19:49
@7amed3li 7amed3li force-pushed the feat/prototype-pollution-detection branch from 222ed5f to afc3df2 Compare February 2, 2026 21:29
@7amed3li
Copy link
Contributor Author

7amed3li commented Feb 2, 2026

Really appreciate the review — it’s been teaching me a lot ^_^
I’m still learning where the line is between adding a helper and keeping things simple, so this kind of feedback helps a lot.

@7amed3li
Copy link
Contributor Author

7amed3li commented Feb 4, 2026

@fraxken Let me know if any additional changes are needed from my side.

@fraxken
Copy link
Member

fraxken commented Feb 4, 2026

@7amed3li Some reviews are not fixed

@7amed3li 7amed3li force-pushed the feat/prototype-pollution-detection branch from 40eb76a to d9ac53c Compare February 4, 2026 18:46
@fraxken
Copy link
Member

fraxken commented Feb 4, 2026

You need to rebase, I removed the @nodesecure/estree-ast-utils workspace

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add prototype pollution detection for __proto__ usage

2 participants