# eslint-config-sdl

> SDL recommended configuration for ESLint

Latest version **1.0.3** (published 2020-07-22) · ISC license · 0 weekly downloads

## Install

```sh
npm install eslint-config-sdl
pnpm add eslint-config-sdl
yarn add eslint-config-sdl
bun add eslint-config-sdl
```

## Health

**Score 15/100 (F)** — status: abandoned.

Positive: no vulnerabilities.

Warnings: low downloads; no types; no esm support.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 1.0.3 |
| Published | 2020-07-22 |
| First published | 2019-08-19 |
| Weekly downloads | 0 |
| License | ISC |
| TypeScript types | none |
| Module format | CommonJS |
| Dependencies | 0 |
| Unpacked size | 10.3 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| Author | Microsoft |
| Maintainers | bogdan.andronache |

## Links

- npm: https://www.npmjs.com/package/eslint-config-sdl
- npm.io page: https://npm.io/package/eslint-config-sdl

## Recent versions

- 1.0.3 (latest) — 2020-07-22
- 1.0.2 — 2019-12-17
- 1.0.1 — 2019-08-19
- 1.0.0 — 2019-08-19

## README

# eslint-config-sdl

A set of ESLint [Shareable Configs](http://eslint.org/docs/developer-guide/shareable-configs) for JavaScript and TypeScript applications that focuses on common security issues and misconfigurations. 

Configs are intended as a baseline for projects that follow [Microsoft Security Development Lifecycle (SDL)](https://www.microsoft.com/en-us/securityengineering/sdl) and use ESLint to perform [Static Analysis Security Testing (SAST)](https://www.microsoft.com/en-us/securityengineering/sdl/practices#practice9).

## Install
```bash
npm install eslint-config-sdl
```

## Usage
See [Shareable Configs](http://eslint.org/docs/developer-guide/shareable-configs) on the
official ESLint website.

## Shareable Configs

 | Config | Description |
 | -- | -- |
 | [sdl-required.json](./sdl-required.json) | Set of required rules that should run on every project. |
 | [sdl-recommended.json](./sdl-recommended.json) | Extension to sdl-required config that adds additional rules to increase coverage with potentially higher false positive rate. |

## Enabled Rules

| Rule | Applicability | Severity | Description |
| --- | --- | --- | --- | --- |
| [no-caller](https://eslint.org/docs/rules/no-caller) | Required for JS and TS | Error | Bans usage of deprecated functions `arguments.caller()` and `arguments.callee` that could potentially allow access to call stack. |
| [no-delete-var](https://eslint.org/docs/rules/no-delete-var) | Required for JS and TS | Error | Bans usage of operator `delete` on variables as it can lead to unexpected behavior. |
| [no-eval](https://eslint.org/docs/rules/no-eval) | Required for JS and TS | Error | Bans usage of [`eval()`](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/eval) that allows code exection from string argument. |
| [no-implied-eval](https://eslint.org/docs/rules/no-implied-eval) | Required for JS | Error | Bans usage of `setTimeout()`, `setInterval()` and `execScript()`. These functions are similar to `eval()` and prone to code execution. |
| [no-new-func](https://eslint.org/docs/rules/no-new-func) | Required for JS | Error | Bans calling `new Function()` as it's similar to `eval()` and prone to code execution. |
| [no-restricted-syntax](https://eslint.org/docs/rules/no-restricted-syntax) | Required fo JS and TS | Error | This is a generic rule we use for banning specific patterns in the code that are not yet covered by custom rules: <br> - Call to `document.write` or `document.writeln` - These methods pass HTML directly into DOM without validation and are prone to script-injection. <br> - Access to `document.cookie` - Cookies often contain sensitive information, access to this property needs to be strictly controlled. <br> - Assignment to `document.domain` - Any assignment to this property must be strictly controlled to make sure the value is on a list of allowed sites. <br> - Assignment to `innerHTML` or `outerHTML` property - Assignment to these properties is done without sanitization and is prone to script-injection. <br> - Call to `.html()` method - Frameworks such as jQuery implement this method to allow passing unsanitized content into DOM. Calls should be reviewed properly to avoid script-injection. <br> - Call to `MSApp.execUnsafeLocalFunction()`, `WinJS.Utilities.setInnerHTMLUnsafe()`, `WinJS.Utilities.setOuterHTMLUnsafe` - Disabling auto-sanitization can lead to script-injection. <br> - Call to `$sceProvider.enabled(false)` - This method disables [Strict Contextual Escaping](https://docs.angularjs.org/api/ng/service/$sce) which is a built-in mechanism in Angular framework for prevention against script-injection. |
| [react/no-danger](https://github.com/yannickcr/eslint-plugin-react/blob/master/docs/rules/no-danger.md) | Required for TS | Error | Bans usage of `dangerouslySetInnerHTML` property in React as it allows passing unsanitized HTML in DOM. |
| [@typescript-eslint/no-implied-eval](https://github.com/typescript-eslint/typescript-eslint/blob/master/packages/eslint-plugin/docs/rules/no-implied-eval.md) | Required for TS | Error | Similar to built-in ESLint rule `no-implied-eval`. Bans usage of `setTimeout()`, `setInterval()`, `setImmediate()`, `execScript()` or `new Function()` as they are similar to `eval()` and allow code execution from string arguments. |

---
_Source: https://npm.io/package/eslint-config-sdl · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
