diff --git a/ruby/ql/lib/codeql/ruby/security/UnsafeDeserializationCustomizations.qll b/ruby/ql/lib/codeql/ruby/security/UnsafeDeserializationCustomizations.qll index f56544a8d8b..dfe448e7b5b 100644 --- a/ruby/ql/lib/codeql/ruby/security/UnsafeDeserializationCustomizations.qll +++ b/ruby/ql/lib/codeql/ruby/security/UnsafeDeserializationCustomizations.qll @@ -49,7 +49,8 @@ module UnsafeDeserialization { /** * An argument in a call to `YAML.load` or `YAML.load_file`, considered a sink - * for unsafe deserialization. As the `YAML` module is an alias of `Psych` in + * for unsafe deserialization. The `YAML` module is an alias of `Psych` in + * recent versions of Ruby. */ class YamlLoadArgument extends Sink { YamlLoadArgument() {