diff --git a/lib/brakeman/checks/check_sql.rb b/lib/brakeman/checks/check_sql.rb index 0aaf790f9fd44fa8604e07ddbf01923a300d694f..5bed92ad09bfd646b2c471b2f8ab590596e2e971 100644 --- a/lib/brakeman/checks/check_sql.rb +++ b/lib/brakeman/checks/check_sql.rb @@ -454,7 +454,10 @@ class Brakeman::CheckSQL < Brakeman::BaseCheck end end - IGNORE_METHODS_IN_SQL = Set[:id, :table_name, :to_i, :to_f] + IGNORE_METHODS_IN_SQL = Set[:id, :table_name, :to_i, :to_f, + :sanitize_sql, :sanitize_sql_array, :sanitize_sql_for_assignment, + :sanitize_sql_for_conditions, :sanitize_sql_hash, + :sanitize_sql_hash_for_assignment, :sanitize_sql_hash_for_conditions] def safe_value? exp return true unless sexp? exp