Skip to content

EX0020 : Specified text found in comments

Detect comments that match specific patterns to prevent potential issues in the SQL code.

In T-SQL and SQL Server development, comments are used to explain code and enhance readability. However, certain comment patterns might indicate potential problems, like obsolete code, security concerns, or poorly explained logic.

For example:

-- Temporary fix.
SELECT * FROM Employee;

This comment, “Temporary fix,” suggests that the code is a placeholder or workaround, which might never be revisited or replaced if not properly documented and tracked.

  • Comments with vague or concerning patterns can lead to security vulnerabilities if sensitive logic changes go undocumented.

  • Misleading or outdated comments increase maintenance complexity, as future developers might rely on incorrect information.

This section provides guidance on addressing potentially problematic comment patterns detected by the SQL Enlight rule ex0020 .

Follow these steps to identify and correct problematic comments in your SQL code:

1.Review all comments flagged by EX0020 to understand the context and intent. Identify if the comments suggest temporary fixes, security concerns, or obsolete code.

2.Replace vague comments with detailed explanations. Ensure that comments accurately describe the purpose and logic of the associated code.

3.Document any temporary workarounds clearly, specifying conditions for when they should be revisited or replaced.

4.Remove or update obsolete comments that no longer apply to current code changes to prevent misinformation.

For example, update the following code:

-- Temporary fix: Should be reviewed after performance testing
SELECT * FROM Employee WHERE Status = 'Active';

The rule has a Batch scope and is applied only on the SQL script.

| Name | Description | Default Value | | ——————— | –––––––––––––––––––––––––––––––– | ———–– | –– | –– | — | —– | | CommentTextMatchRegex | Regular expression that to be matched in comments. | regexp:Fix | Hack | Todo | Bug | Issue | | IgnoreCase | The parameter specifies whether to ignore the matched text case. | yes |

The rule does not need Analysis Context or SQL Connection.

5 minutes per issue.

Explicit Rules

There is no additional info for this rule.

CREATE PROCEDURE [dbo].[uspGetWhereUsedProductID]
@StartProductID [int]
, @CheckDate [datetime]
AS
BEGIN
SET NOCOUNT ON;
DECLARE @result int
BEGIN TRY
SELECT @result = 1/0 -- bug
/*
some other comment
*/
END TRY
BEGIN CATCH
-- todo: add error handling
PRINT 'Division by 0'
END CATCH
SET @result = 5 -- hack
RETURN @result;
END
  Message Line Column
1 EX0020 : Text bug found inside comments. 10 22
2 EX0020 : Text todo found inside comments. 16 2
3 EX0020 : Text hack found inside comments. 20 17

Analysis Rules