https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42585 --- Comment #21 from Kyle M Hall (khall) <kyle@bywatersolutions.com> --- (In reply to Andrew Fuerste-Henry from comment #12) Thanks Andrew! All three should be fixed! The no findings on your query was two bugs. correlated_subquery pulled the subquery body out with a regex that stopped at the first closing paren, s the COUNT(*) hid it. It counts bracket depth now. And scale dependent findings were *dropped* on a small database instead of shown. They come back suppressed now, with the row estimate, under a "Not a problem on this database" toggle, and don't count toward the severity. Regular expressions be hard! The size limit was looking at how big the tables are, not how much of them the query reads. It uses the EXPLAIN row estimate now, capped by a trailing LIMIT when the plan can stream rows straight out. So "SELECT * FROM items LIMIT 10" is quiet, but "ORDER BY RAND() LIMIT 1" still warns, because the sort reads every row before the LIMIT applies. On the password column, is_sql_valid catches one named in the SQL text and I had that covered. A wildcard ( SELECT * FROM borrowers ) isn't caught until execute_query looks at the result column names. forbidden_column expands wildcards against the schema now, so your query reports borrowers.password, borrowers.secret and borrowers.overdrive_auth_token. Please give it another shot and let me know how it goes! -- You are receiving this mail because: You are watching all bug changes.