Changes since 8.0.6:
- Update SonarQube report to use generic issue format (fangxing)
- Include regex code in validation warnings (Eliot Sykes)
- Check validation regexes in non-activerecord models (Eliot Sykes)
- Skip top-level vendor directory before recursive globbing (Conor O’Donnell)
- Support Rails 7.1+ positional enum syntax in SQL injection check (Michael Vogl/Yuriy Tumanov)
- Recognize
Haml::AttributeBuilder.build_classas an escaped output (Yuriy Tumanov) - Fix frozen string error (Shai Coleman)
- Better help and error message for
--ensure-latest(#2036)
SonarQube Report Format
When using the Sonar format report (-f sonar), Brakeman will now use the newer generic issues report.
In theory, you could also use the SARIF report (-f sarif) but this has not been tested.
Thanks Fangxing!
(changes)
Validation Regex Changes
Previously, Brakeman was not including the validation regex itself when warning about insufficient anchoring. This could cause two different validation warnings to have the same fingerprint.
validates_format_of :something, /^something$/
This has been rectified, thanks to Eliot Sykes. However, this will mean fingerprint values will change for existing validation regex warnings.
Eliot also expanded Brakeman’s check for insufficient anchoring in validation regexes to include non-ActiveRecord models.
(changes)
(changes)
Better Vendor Directory Skipping
Brakeman skips the top-level vendor directory by default or if --skip-vendor is used.
However, there were performance issues because while files in the directory were skipped, they were still searched for matching file names.
Conor noticed the performance problem and fixed it!
(changes)
Newer Enum Support
Michael Vogl added support for the newer (Rails 7.1+) syntax for enums:
enum :status, active: 0, archived: 1
And Yuriy Tumanov fixed up the tests for it.
(changes)
More Haml Builders
Yuriy also fixed an issue where Haml::AttributeBuilder.build_class was falsely being reported as vulnerable to cross-site scripting.
(changes)
- Update SonarQube report to use generic issue format (fangxing)
- Include regex code in validation warnings (Eliot Sykes)
- Check validation regexes in non-activerecord models (Eliot Sykes)
- Skip top-level vendor directory before recursive globbing (Conor O’Donnell)
- Support Rails 7.1+ positional enum syntax in SQL injection check (Michael Vogl/Yuriy Tumanov)
- Recognize
Haml::AttributeBuilder.build_classas an escaped output (Yuriy Tumanov) - Fix frozen string error (Shai Coleman)
- Better help and error message for
--ensure-latest(#2036
Checksums
The SHA256 sums for this release are:
Reporting Issues
Thank you to everyone who reported bugs and contributed to this release!
Please report any issues with this release. Take a look at this guide to reporting Brakeman problems.
Hang out on GitHub for questions and discussion.