| category | minorAnalysis |
|---|
- The
cs/log-forgingquery no longer treats arguments to extension methods with source code onILoggertypes as sinks. Instead, taint is tracked interprocedurally through extension method bodies, reducing false positives when extension methods sanitize input internally.