My project code is scanned by fortify, it report that the character of $ has the risk about sql injection. But the code is generated by mybatis-gererator automatically, the $ is