Skip to content

Commit 063c76b

Browse files
committed
apply suggestions from review
1 parent 79a0489 commit 063c76b

File tree

34 files changed

+216
-216
lines changed

34 files changed

+216
-216
lines changed

ruby/ql/lib/codeql/ruby/security/CommandInjectionCustomizations.qll

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,7 @@ module CommandInjection {
3333
class RemoteFlowSourceAsSource extends Source {
3434
RemoteFlowSourceAsSource() { this instanceof RemoteFlowSource }
3535

36-
override string getSourceType() { result = "a user-provided value" }
36+
override string getSourceType() { result = "user-provided value" }
3737
}
3838

3939
/**

ruby/ql/src/experimental/cwe-807/ConditionalBypass.ql

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -78,5 +78,5 @@ predicate isTaintedGuardForSensitiveAction(
7878

7979
from DataFlow::PathNode source, DataFlow::PathNode sink, SensitiveAction action
8080
where isTaintedGuardForSensitiveAction(sink, source, action)
81-
select sink.getNode(), source, sink, "This condition guards a sensitive $@, but $@ controls it.",
82-
action, "action", source.getNode(), "a user-provided value"
81+
select sink.getNode(), source, sink, "This condition guards a sensitive $@, but a $@ controls it.",
82+
action, "action", source.getNode(), "user-provided value"

ruby/ql/src/queries/security/cwe-022/PathInjection.ql

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -22,5 +22,5 @@ import DataFlow::PathGraph
2222

2323
from Configuration cfg, DataFlow::PathNode source, DataFlow::PathNode sink
2424
where cfg.hasFlowPath(source, sink)
25-
select sink.getNode(), source, sink, "This path depends on $@.", source.getNode(),
26-
"a user-provided value"
25+
select sink.getNode(), source, sink, "This path depends on a $@.", source.getNode(),
26+
"user-provided value"

ruby/ql/src/queries/security/cwe-078/CommandInjection.ql

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,5 +21,5 @@ from Configuration config, DataFlow::PathNode source, DataFlow::PathNode sink, S
2121
where
2222
config.hasFlowPath(source, sink) and
2323
sourceNode = source.getNode()
24-
select sink.getNode(), source, sink, "This command depends on $@.", sourceNode,
24+
select sink.getNode(), source, sink, "This command depends on a $@.", sourceNode,
2525
sourceNode.getSourceType()

ruby/ql/src/queries/security/cwe-079/ReflectedXSS.ql

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -19,5 +19,5 @@ import DataFlow::PathGraph
1919

2020
from ReflectedXss::Configuration config, DataFlow::PathNode source, DataFlow::PathNode sink
2121
where config.hasFlowPath(source, sink)
22-
select sink.getNode(), source, sink, "Cross-site scripting vulnerability due to $@.",
23-
source.getNode(), "a user-provided value"
22+
select sink.getNode(), source, sink, "Cross-site scripting vulnerability due to a $@.",
23+
source.getNode(), "user-provided value"

ruby/ql/src/queries/security/cwe-089/SqlInjection.ql

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -34,5 +34,5 @@ class SqlInjectionConfiguration extends TaintTracking::Configuration {
3434

3535
from SqlInjectionConfiguration config, DataFlow::PathNode source, DataFlow::PathNode sink
3636
where config.hasFlowPath(source, sink)
37-
select sink.getNode(), source, sink, "This SQL query depends on $@.", source.getNode(),
38-
"a user-provided value"
37+
select sink.getNode(), source, sink, "This SQL query depends on a $@.", source.getNode(),
38+
"user-provided value"

ruby/ql/src/queries/security/cwe-094/CodeInjection.ql

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -22,5 +22,5 @@ from Configuration config, DataFlow::PathNode source, DataFlow::PathNode sink, S
2222
where
2323
config.hasFlowPath(source, sink) and
2424
sourceNode = source.getNode()
25-
select sink.getNode(), source, sink, "This code execution depends on $@.", source.getNode(),
26-
"a user-provided value"
25+
select sink.getNode(), source, sink, "This code execution depends on a $@.", source.getNode(),
26+
"user-provided value"

ruby/ql/src/queries/security/cwe-117/LogInjection.ql

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,5 +17,5 @@ import codeql.ruby.security.LogInjectionQuery
1717

1818
from LogInjectionConfiguration config, DataFlow::PathNode source, DataFlow::PathNode sink
1919
where config.hasFlowPath(source, sink)
20-
select sink.getNode(), source, sink, "Log entry depends on $@.", source.getNode(),
21-
"a user-provided value"
20+
select sink.getNode(), source, sink, "Log entry depends on a $@.", source.getNode(),
21+
"user-provided value"

ruby/ql/src/queries/security/cwe-1333/PolynomialReDoS.ql

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -26,6 +26,6 @@ where
2626
sinkNode = sink.getNode() and
2727
regexp = sinkNode.getRegExp()
2828
select sinkNode.getHighlight(), source, sink,
29-
"This $@ that depends on $@ may run slow on strings " + regexp.getPrefixMessage() +
29+
"This $@ that depends on a $@ may run slow on strings " + regexp.getPrefixMessage() +
3030
"with many repetitions of '" + regexp.getPumpString() + "'.", regexp, "regular expression",
31-
source.getNode(), "a user-provided value"
31+
source.getNode(), "user-provided value"

ruby/ql/src/queries/security/cwe-1333/RegExpInjection.ql

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -22,5 +22,5 @@ import codeql.ruby.security.regexp.RegExpInjectionQuery
2222

2323
from Configuration cfg, DataFlow::PathNode source, DataFlow::PathNode sink
2424
where cfg.hasFlowPath(source, sink)
25-
select sink.getNode(), source, sink, "This regular expression depends on $@.", source.getNode(),
26-
"a user-provided value"
25+
select sink.getNode(), source, sink, "This regular expression depends on a $@.", source.getNode(),
26+
"user-provided value"

0 commit comments

Comments
 (0)