Commit 13ea1ae
committed
Fix SQL injection false positives: require SQL structure in pattern
The regex now requires SQL keyword + structure (SELECT...FROM,
INSERT INTO, UPDATE...SET, DELETE FROM, etc) instead of just matching
bare keywords like DELETE or SELECT. This eliminates false positives
like res.send('delete ' + name) being flagged as SQL injection.
Applied to JS, Go, and Python rules. All test fixtures still detected.
Express.js: 0 critical (was 1 false positive).
none1 parent 873fdb3 commit 13ea1ae
3 files changed
Lines changed: 7 additions & 4 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
103 | 103 | | |
104 | 104 | | |
105 | 105 | | |
106 | | - | |
| 106 | + | |
107 | 107 | | |
108 | 108 | | |
109 | 109 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
210 | 210 | | |
211 | 211 | | |
212 | 212 | | |
213 | | - | |
214 | | - | |
| 213 | + | |
| 214 | + | |
| 215 | + | |
| 216 | + | |
| 217 | + | |
215 | 218 | | |
216 | 219 | | |
217 | 220 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
183 | 183 | | |
184 | 184 | | |
185 | 185 | | |
186 | | - | |
| 186 | + | |
187 | 187 | | |
188 | 188 | | |
189 | 189 | | |
| |||
0 commit comments