You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
You should be very careful when allowing user sent data to be used as part of LIKE query, since they allow to perform LIKE-injections.
During a code review today, I thought it would have been nice to be warned about that, and that the infrastructure available in Credo could probably help detect cases like:
I am not sure exactly how, and if this is "easy" to implement as a Credo check, but it would be quite nice to get such alerts. Maybe a security scanner is a better place?
The text was updated successfully, but these errors were encountered:
What do you want Credo to do?
See:
During a code review today, I thought it would have been nice to be warned about that, and that the infrastructure available in Credo could probably help detect cases like:
I am not sure exactly how, and if this is "easy" to implement as a Credo check, but it would be quite nice to get such alerts. Maybe a security scanner is a better place?
The text was updated successfully, but these errors were encountered: