Files
codeql/ruby/ql/lib/change-notes/2023-03-13-rails-sinks.md
2023-03-13 18:57:55 +13:00

334 B

category
category
minorAnalysis
  • The Active Record query methods reorder and count_by_sql are now recognised as SQL executions.
  • Calls to ActiveRecord::Connection#execute, including those via subclasses, are now recognised as SQL executions.
  • Data flow through ActionController::Parameters#require is now tracked properly.