FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

Flag up functionality that may not exist in default setup workflows by henrymercer · Pull Request #1678 · github/codeql-action · GitHub

Flag up functionality that may not exist in default setup workflows - #1678

Merged
henrymercer merged 9 commits into
mainfrom
henrymercer/default-setup-safeguarding
May 31, 2023
Merged

henrymercer merged 9 commits into
mainfrom
henrymercer/default-setup-safeguarding

Conversation

henrymercer commented May 12, 2023
edited
Loading

Copy link
Copy Markdown
Contributor

This PR adds two internal CodeQL queries to identify environment variables and Actions context variables that may not work with default setup.

While we're here, we switch libraryPathDependencies to dependencies and modify the "Inconsistent Action inputs" query to ignore internal Actions.

Merge / deployment checklist

  • Confirm this change is backwards compatible with existing workflows.
  • Confirm the readme has been updated if necessary.
  • Confirm the changelog has been updated if necessary.

Comment thread queries/codeql-pack.yml
henrymercer changed the title Add CodeQL queries to safeguard against using functionality that may not exist in default setup workflows Flag up functionality that may not exist in default setup workflows May 30, 2023
henrymercer marked this pull request as ready for review May 30, 2023 21:06
henrymercer requested a review from a team as a code owner May 30, 2023 21:06

aeisenberg left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Choose a reason Spam Abuse Off Topic Outdated Duplicate Resolved Low Quality

Nice. I think I understand the QL.

Comment thread queries/default-setup-event-context.ql Outdated
Comment thread queries/default-setup-event-context.ql Outdated
henrymercer requested a review from aeisenberg May 31, 2023 13:25

aeisenberg left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Choose a reason Spam Abuse Off Topic Outdated Duplicate Resolved Low Quality

NIce.

henrymercer merged commit 89c4c9e into main May 31, 2023
henrymercer deleted the henrymercer/default-setup-safeguarding branch May 31, 2023 16:33
github-actions Bot mentioned this pull request Jun 1, 2023
6 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants


Back | FazBrowse Home | New Git URL