Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Actions: Sequester issue_comment triggered untrusted checkout from other triggers #18838

Open
wants to merge 7 commits into
base: main
Choose a base branch
from

Merge branch 'kyfast/untrusted-checkout-refinements' of https://githu…

4a50cce
Select commit
Loading
Failed to load commit list.
Open

Actions: Sequester issue_comment triggered untrusted checkout from other triggers #18838

Merge branch 'kyfast/untrusted-checkout-refinements' of https://githu…
4a50cce
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / CodeQL completed Feb 25, 2025 in 10s

5 configurations not found

Warning: Code scanning may not have found all the alerts introduced by this pull request, because 5 configurations present on refs/heads/main were not found:

Actions workflow (rust-analysis.yml)

  • ❓  .github/workflows/rust-analysis.yml:analyze/language:rust

Actions workflow (csv-coverage-metrics.yml)

  • ❓  .github/workflows/csv-coverage-metrics.yml:publish-csharp
  • ❓  .github/workflows/csv-coverage-metrics.yml:publish-java

Actions workflow (codeql-analysis.yml)

  • ❓  .github/workflows/codeql-analysis.yml:CodeQL-Build

Actions workflow (cpp-swift-analysis.yml)

  • ❓  .github/workflows/cpp-swift-analysis.yml:CodeQL-Build

New alerts in code changed by this pull request

  • 5 warnings

See annotations below for details.

View all branch alerts.

Annotations

Check warning on line 8 in actions/ql/lib/codeql/actions/security/UntrustedCheckoutQuery.qll

See this annotation in the file changed.

Code scanning / CodeQL

Singleton set literal Warning

Singleton set literal can be replaced by its member.

Check warning on line 55 in actions/ql/src/Security/CWE-829/UntrustedCheckoutIssueCommentCritical.ql

See this annotation in the file changed.

Code scanning / CodeQL

Alert message style violation Warning

Alert message should end with a full stop.

Check warning on line 29 in actions/ql/src/Security/CWE-829/UntrustedCheckoutIssueCommentHigh.ql

See this annotation in the file changed.

Code scanning / CodeQL

Alert message style violation Warning

Alert message should end with a full stop.

Check warning on line 1 in actions/ql/test/query-tests/Security/CWE-829/UntrustedCheckoutIssueCommentCritical.qlref

See this annotation in the file changed.

Code scanning / CodeQL

Query test without inline test expectations Warning test

Query test does not use inline test expectations.

Check warning on line 1 in actions/ql/test/query-tests/Security/CWE-829/UntrustedCheckoutIssueCommentHigh.qlref

See this annotation in the file changed.

Code scanning / CodeQL

Query test without inline test expectations Warning test

Query test does not use inline test expectations.