Actions: Sequester issue_comment triggered untrusted checkout from other triggers #18838
5 configurations not found
Warning: Code scanning may not have found all the alerts introduced by this pull request, because 5 configurations present on refs/heads/main
were not found:
Actions workflow (rust-analysis.yml
)
- ❓
.github/workflows/rust-analysis.yml:analyze/language:rust
Actions workflow (csv-coverage-metrics.yml
)
- ❓
.github/workflows/csv-coverage-metrics.yml:publish-csharp
- ❓
.github/workflows/csv-coverage-metrics.yml:publish-java
Actions workflow (codeql-analysis.yml
)
- ❓
.github/workflows/codeql-analysis.yml:CodeQL-Build
Actions workflow (cpp-swift-analysis.yml
)
- ❓
.github/workflows/cpp-swift-analysis.yml:CodeQL-Build
New alerts in code changed by this pull request
- 5 warnings
See annotations below for details.
Annotations
Check warning on line 8 in actions/ql/lib/codeql/actions/security/UntrustedCheckoutQuery.qll
Code scanning / CodeQL
Singleton set literal Warning
Check warning on line 55 in actions/ql/src/Security/CWE-829/UntrustedCheckoutIssueCommentCritical.ql
Code scanning / CodeQL
Alert message style violation Warning
Check warning on line 29 in actions/ql/src/Security/CWE-829/UntrustedCheckoutIssueCommentHigh.ql
Code scanning / CodeQL
Alert message style violation Warning
Code scanning / CodeQL
Query test without inline test expectations Warning test
Code scanning / CodeQL
Query test without inline test expectations Warning test