https://github.com/soutaro/querly Rubyãæ§æ解æããASTã«å¯¾ãã¦ç¬èªDSLã§ãã¿ã¼ã³ãããï¼ã¡ãã»ã¼ã¸ãåºããã¼ã« ããã¸ã§ã¯ãåºæã®äºæ ã«é æ ®ããLinterã¨ãã¦ä½¿ãã false positive ä¸çã§æ³¨æåèµ·ã¨ãã¦ä½¿ã ãã¨ãã°Kibelaã® querly.yaml ããä¸é¨æç²ããã¨ãããªæãã§ãã rules: # ... - id: kibela.order_by_string pattern: - "order(:dstr:)" - "where(:dstr:)" - "find(:dstr:)" - "exists?(:dstr:)" message: "æååã«ããSQLæ§ç¯ã¯æ¬å½ã«å¿ è¦ã§ããï¼ SQL Injection ãå¼ãèµ·ãããªãããã«æ°ãã¤ãã¦ãã ããã" - id: kibela.block_call patter
{{#tags}}- {{label}}
{{/tags}}