Files
codeql/ruby/ql/src/change-notes/released/0.5.0.md
2023-01-05 16:46:44 +00:00

649 B

0.5.0

New Queries

  • Added a new query, rb/stack-trace-exposure, to detect exposure of stack-traces to users via HTTP responses.

Minor Analysis Improvements

  • The AlertSuppression.ql query has been updated to support the new # codeql[query-id] supression comments. These comments can be used to suppress an alert and must be placed on a blank line before the alert. In addition the legacy # lgtm and # lgtm[query-id] comments can now also be placed on the line before an alert.
  • Extended the rb/kernel-open query with following sinks: IO.write, IO.binread, IO.binwrite, IO.foreach, IO.readlines, and URI.open.