Skip to content

Commit 5e5160d

Browse files
committed
add which commands are flagged in the change-note
1 parent fc21128 commit 5e5160d

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

javascript/ql/src/change-notes/2022-09-05-second-order-command-injection.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,3 +4,4 @@ category: newQuery
44
* Added a new query, `js/second-order-command-line-injection`, to detect shell
55
commands that may execute arbitrary code when the user has control over
66
the arguments to a command-line program.
7+
This currently flags up unsafe invocations of git and hg.

0 commit comments

Comments
 (0)