Files
codeql/ruby/ql/lib/change-notes/released/0.3.2.md
2022-07-28 15:45:01 +02:00

284 B

0.3.2

Minor Analysis Improvements

  • Calls to Arel.sql are now recognised as propagating taint from their argument.
  • Calls to ActiveRecord::Relation#annotate are now recognized as SqlExecutions so that it will be considered as a sink for queries like rb/sql-injection.