Files
codeql/ruby/ql/lib/change-notes/released/0.3.2.md
2022-07-28 13:38:35 +00:00

283 B

0.3.2

Minor Analysis Improvements

  • Calls to Arel.sql are now recognised as propagating taint from their argument.
  • Calls to ActiveRecord::Relation#annotate are now recognized asSqlExecutions so that it will be considered as a sink for queries like rb/sql-injection.