@@ -273,11 +273,12 @@ module ModelValidation {
273273 not kind =
274274 [
275275 "open-url" , "jndi-injection" , "ldap-injection" , "sql-injection" , "jdbc-url" ,
276- "log-injection" , "mvel-injection" , "xpath-injection" , "groovy-injection" , "xss" ,
277- "ognl-injection" , "intent-redirection" , "pending-intents" , "url-open-stream" ,
278- "url-redirection" , "create-file" , "read-file" , "write-file" , "hostname-verification" ,
279- "response-splitting" , "information-leak" , "xslt-injection" , "jexl-injection" ,
280- "bean-validation" , "template-injection" , "fragment-injection" , "command-injection"
276+ "log-injection" , "mvel-injection" , "xpath-injection" , "groovy-injection" ,
277+ "html-injection" , "js-injection" , "ognl-injection" , "intent-redirection" ,
278+ "pending-intents" , "url-open-stream" , "url-redirection" , "create-file" , "read-file" ,
279+ "write-file" , "hostname-verification" , "response-splitting" , "information-leak" ,
280+ "xslt-injection" , "jexl-injection" , "bean-validation" , "template-injection" ,
281+ "fragment-injection" , "command-injection"
281282 ] and
282283 not kind .matches ( "regex-use%" ) and
283284 not kind .matches ( "qltest%" ) and
0 commit comments