My project code is scanned by fortify, it report that the character of $ has the risk about sql injection. But the code is generated by mybatis-gererator automatically, the $ is just table's column variate. There is not risk actually but reported. How can i do? The result of report cannot ignore.
2.1m questions
2.1m answers
60 comments
57.0k users