Original issue https://github.com/drewg2009/readableRegex/security/code-scanning/6 We can't whitelist every URL so we may want to sanitize the URL of query params and API check it against a blacklist if needed