Files
codeql/ruby/ql/lib/change-notes/released/0.3.3.md
2022-08-11 11:12:15 +00:00

475 B

0.3.3

Minor Analysis Improvements

  • Calls to methods generated by ActiveRecord associations are now recognised as instantiations of ActiveRecord objects. This increases the sensitivity of queries such as rb/sql-injection and rb/stored-xss.
  • Calls to ActiveRecord::Base.create and ActiveRecord::Base.update are now recognised as write accesses.
  • Arguments to Mime::Type#match? and Mime::Type#=~ are now recognised as regular expression sources.