- The query
java/groovy-injectionnow recognizesgroovy.text.TemplateEngine.createTemplateas a sink. - The queries
java/xxeandjava/xxe-localnow recognize the second argument of calls toXPath.evaluateas a sink. - Experimental sinks for the query "Resolving XML external entity in user-controlled data" (
java/xxe) have been promoted to the main query pack. These sinks were originally submitted as part of an experimental query by @haby0.