This change log includes updates to detectors made in April 2026.
python-llm-improper-output-handling
python-llm-unbounded-consumption
python-llm-system-prompt-leakage
python-prompt-injection-vulnerability
python-llm-vector-embeddings-weaknesses
python-llm-sensitive-information-disclosure
python-untrusted-deserialization
javascript-llm-prompt-injection
javascript-llm-improper-output-handling
javascript-llm-system-prompt-leakage
javascript-llm-sensitive-information-disclosure
javascript-llm-vector-embedding-weaknesses
javascript_llm_unbound_consumption
typescript-llm-prompt-injection
typescript-llm-improper-output-handling
typescript-llm-system-prompt-leakage
typescript-llm-sensitive-information-disclosure
typescript_llm_unbound_consumption
typescript-llm-vector-embedding-weaknesses
scala-deserialization-of-untrusted-data
kotlin-deserialization-config
python-log-injection
python-detect-hardcoded-aws-credentials
python-os-command-injection-hb
python-no-sql-injection
javascript-insecure-random
javascript-os-command-injection-hb
javascript-cross-site-scripting
typescript-os-command-injection-hb
typescript-path-traversal-hb
c-os-command-injection
c-clear-text-protocols
cpp-incorrect-pseudorandom-number-generator
cpp-insufficient-key-size
weak-random-number-generation-csharp-rule
insecure-cryptography-csharp-rule
weak-cipher-algorithm
csharp-untrusted-deserialization
java-unsafe-finalize-method
java-os-command-injection-ide
java-os-command-injection-hb
java-deprecated-cryptographic-classes
java-log-injection-hb
java-no-sql-injection-hb
java-untrusted-load
java-insecure-deserialization-serialization-utils
go-os-command-injection-hb
go-weak-rand-source
go-weak-crypto
go-bad-tls-settings
go-unsafe-deserialization
scala-os-command-injection-hb
scala-insecure-random
scala-hazelcast-symmetric-encryption
kotlin-unsafe-deserialization
php-using-pseudorandom-number
php-openssl-cbc-static-iv
php-weak-crypto
php-mcrypt-use
php-untrusted-deserialization
ruby-insecure-random
ruby-weak-cipher
ruby-untrusted-deserialization
No rules were disabled in April 2026.