diff --git a/ruby/ql/lib/change-notes/2023-03-13-sinatra.md b/ruby/ql/lib/change-notes/2023-03-13-sinatra.md new file mode 100644 index 00000000000..3d888416fb9 --- /dev/null +++ b/ruby/ql/lib/change-notes/2023-03-13-sinatra.md @@ -0,0 +1,6 @@ +--- + category: minorAnalysis +--- +* Accesses of `params` in Sinatra applications are now recognised as HTTP input accesses. +* Data flow is tracked from Sinatra route handlers to ERB files. +* Data flow is tracked between basic Sinatra filters (those without URL patterns) and their corresponding route handlers.