diff --git a/njsscan/rules/semantic_grep/database/nosql_find_injection.yaml b/njsscan/rules/semantic_grep/database/nosql_find_injection.yaml index e2d092a..8a740f2 100644 --- a/njsscan/rules/semantic_grep/database/nosql_find_injection.yaml +++ b/njsscan/rules/semantic_grep/database/nosql_find_injection.yaml @@ -1,6 +1,16 @@ rules: - id: node_nosqli_injection patterns: + - pattern-not-inside: | + $SEQUELIZE = require('sequelize') + ... + $SEQUELIZE(...) + ... + - pattern-not-inside: | + import $SEQUELIZE from 'sequelize' + ... + $SEQUELIZE(...) + ... - pattern-not-inside: | $SANITIZE = require('mongo-sanitize') ...