Puma Scan is a software security Visual Studio extension that provides real time, continuous source code analysis as development teams write code. Vulnerabilities are immediately displayed in the development environment as spell check and compiler warnings, preventing security bugs from entering your applications.
SEC0108 is regarding SQL injection when using string concatenation. However, the analyzer is false reporting when a constant value is passed into the procedure;
SEC0108 is regarding SQL injection when using string concatenation. However, the analyzer is false reporting when a constant value is passed into the procedure;
Note that using the procedure name instead of the constant does not report a warning.