Files
codeql/ruby/ql/lib/change-notes/2024-02-20-activerecord-sql-sink-arguments.md
2024-03-06 12:07:33 -08:00

227 B

category
category
minorAnalysis
  • Additional arguments beyond the first of calls to the ActiveRecord methods select, reselect, order, reorder, joins, group, and pluck are now recognized as sql injection sinks.