- Fixed a bug causing every expression in the database to be considered a system-command execution sink when calls to any of the following methods exist:
- The
spawn
,fspawn
,popen4
,pspawn
,system
,_pspawn
methods and the backtick operator from thePOSIX::spawn
gem. - The
execute_command
,rake
,rails_command
, andgit
methods inRails::Generation::Actions
.
- The
- Improved modeling of sensitive data sources, so common words like
certain
andsecretary
are no longer considered a certificate and a secret (respectively).