From d0bdbe65ef8aecf96bde5aba33c32a18b2b02494 Mon Sep 17 00:00:00 2001 From: Alex Ford Date: Sun, 9 Oct 2022 22:47:52 +0100 Subject: [PATCH] Ruby: ActiveJob::Serializers.deserialize changenote --- .../2022-10-09-activejob-serializers-deserialize.md | 4 ++++ 1 file changed, 4 insertions(+) create mode 100644 ruby/ql/lib/change-notes/2022-10-09-activejob-serializers-deserialize.md diff --git a/ruby/ql/lib/change-notes/2022-10-09-activejob-serializers-deserialize.md b/ruby/ql/lib/change-notes/2022-10-09-activejob-serializers-deserialize.md new file mode 100644 index 00000000000..4d0be19e67f --- /dev/null +++ b/ruby/ql/lib/change-notes/2022-10-09-activejob-serializers-deserialize.md @@ -0,0 +1,4 @@ +--- +category: minorAnalysis +--- +* `ActiveJob::Serializers.deserialize` is considered to be a code execution sink.