I have this regex to test if the user input is valid:
value.length === 0 ||
value === '-' ||
(!isNaN(parseFloat(value)) && /^-?\d+\.?\d*$/.test(value))
The main point is in the regex: /^-?\d+\.?\d*$/. However sonarcloud is feeling it as a security hotspot saying:
Make sure the regex used here, which is vulnerable to super-linear runtime due to backtracking, cannot lead to denial of service.
I guess it's because of the double digit test, but I couldn't find a way to avoid it. Is it a security threat, or harmless?