Merge pull request #5485 from RasmusWL/django-queryset-chains

Approved by tausbn
This commit is contained in:
CodeQL CI
2021-04-12 08:49:31 -07:00
committed by GitHub
3 changed files with 55 additions and 77 deletions

View File

@@ -0,0 +1,2 @@
lgtm,codescanning
* Improved modeling of `django` to recognize QuerySet chains such as `User.objects.using("db-name").exclude(username="admin").extra("some sql")`. This can lead to new results for `py/sql-injection`.