github / github/codeql

Issue in labeling the correct place of the alert in sql injection queries

未关闭
#3,623 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
Java question
主要语言
CodeQL
星标
10.1k
派生
2.1k
平均合并
2 天 15 小时
30 天内合并 PR
141

描述

Hello,

I would like to report an issue in sql injection queries, where LGTM seems to fail to report the correct location of the error in the codeline.
The following project [jamalmfarhat/lgtm-sql-injection-issue](https://lgtm.com/projects/g/jamalmfarhat/lgtm-sql-injection-issue/?mode=list) was created to replicate the problem.
In the example shown there, our security expert thinks that LGTM should label "Step 4" as the correct location of the alert.
Can you please check?

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。