- The query
java/weak-cryptographic-algorithmno longer alerts aboutRSA/ECBalgorithm strings.
- The query
java/tainted-permissions-checknow uses threat models. This means thatlocalsources are no longer included by default for this query, but can be added by enabling thelocalthreat model. - Added more
org.apache.commons.io.FileUtils-related sinks to the path injection query.