diff --git a/tests/assets/rules/semgrep/deserialization/object_deserialization.java b/tests/assets/rules/semgrep/deserialization/object_deserialization.java index 5ab74a0..51c0acc 100644 --- a/tests/assets/rules/semgrep/deserialization/object_deserialization.java +++ b/tests/assets/rules/semgrep/deserialization/object_deserialization.java @@ -16,8 +16,7 @@ public UserData deserializeObject(InputStream receivedFile) throws IOException, } public UserData deserializeObject(InputStream receivedFile) throws IOException, ClassNotFoundException { - // this pattern not yet working. See https://github.com/returntocorp/semgrep/issues/717 - // This should have a To Do comment, but I want this rule available so I'm leaving it out for now. + // ruleid:object_deserialization try (ObjectInputStream in = new ObjectInputStream(receivedFile)) { return (UserData) in.readObject(); } catch (IOException e) {