CodeQL library for Ruby
codeql/ruby-all 0.8.15-dev (changelog, source)
Search

Module SqlInjection

Provides default sources, sinks and sanitizers for detecting SQL injection vulnerabilities, as well as extension points for adding your own.

Import path

import codeql.ruby.security.SqlInjectionCustomizations

Classes

Sanitizer

A sanitizer for SQL injection vulnerabilities.

Sink

A data flow sink for SQL injection vulnerabilities.

Source

A data flow source for SQL injection vulnerabilities.

StringConstArrayInclusionCallAsSanitizer

An inclusion check against an array of constant strings, considered as a sanitizer-guard.