Skip to content
← All rules
SecurityData protection

security/no-sensitive-data-exposure

Response, render, file-transfer, and redirect sinks should expose only visibly projected, masked, redacted, or sanitized sensitive values.

responsesprivacyredaction
TypeScript
res.json({ user, passwordHash: user.passwordHash });
Finding

Disallow sensitive data sent through output sinks.

Setup

Install the package, register its plugin factory, then enable the rule.

Install the package

pnpm add -D @scruple/security

Register the plugin

In scruple.config.ts, register the factory under the security namespace used by the rule ID.

import { security } from "@scruple/security";

plugins: {
  "security": security(),
},

Enable the rule

"security/no-sensitive-data-exposure": "warn"
Package
@scruple/security
Default threshold
0.9
Minimum confidence
0.75

Released under the MIT License.