build1 publisher
A name-matching SQL scanner missed four of five documented injection CVEs
inlet finds Python SQL call sites by matching names, and in four of five packages with documented injection CVEs the vulnerable string reached the database through a framework helper instead. Its author published the 0 for 5.
Publishers:dev.to
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap−20
- Incentives45
- Confidence50