Python: Model QuerySet chains in django

This commit is contained in:
Rasmus Wriedt Larsen
2021-03-22 14:36:29 +01:00
parent 701b935564
commit c8a6e837b5
3 changed files with 54 additions and 78 deletions

View File

@@ -0,0 +1,2 @@
lgtm,codescanning
* Improved modeling of `django` to recognize QuerySet chains such as `User.objects.using("db-name").exclude(username="admin").extra("some sql")`. This can lead to new results for `py/sql-injection`.