Your ESLint security plugin is missing 58% of vulnerability classes — zero rules for 7 of 12. I have proof, and a correction: my own headline said 80%.
A 4-way benchmark on one fixture (12 vulnerability classes): Oxlint's built-in rules, eslint-plugin-security, the Interlace plugins on ESLint, and the same Interlace rules on Oxlint. eslint-plugin-security has rules for 5 of 12 classes — a 58% class-coverage gap. The URL says 80% because the original headline did; the body stands behind the checkable number.
#security#node#devsecops+1