In this sample lets validate a real sql injection - use a popular DB framework - make this VERY lightweight nothing fancy - just needs to highlight calling an execute query without parameterization ...
This is the behavior in every version I tried (5.9.3 and 5.4.5), and I reviewed the FAQ for entries about "decorator" mark the second decorator as wrong, or at least have the language-server exit ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results