Files
codeql/ruby/ql/test/library-tests/frameworks/railties/Railties.rb
Harry Maclean e1dcc207b4 Ruby: Model methods in Rails::Generators::Actions
These methods are sinks for command injection.
2022-06-20 13:36:09 +12:00

15 lines
207 B
Ruby

class Foo
include Rails::Generators::Actions
def foo
execute_command(:rake, "test")
execute_command(:rails, "server")
rake("test")
rails_command("server")
git("status")
end
end