Skip to content

Commit 44b1bc9

Browse files
Merge branch 'main' into jeongsoolee09/refine-amdmodule
2 parents c327e6f + 9b0854e commit 44b1bc9

File tree

776 files changed

+60523
-6248
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

776 files changed

+60523
-6248
lines changed
Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
ql/actions/ql/src/Security/CWE-077/EnvPathInjectionCritical.ql
2+
ql/actions/ql/src/Security/CWE-077/EnvVarInjectionCritical.ql
3+
ql/actions/ql/src/Security/CWE-094/CodeInjectionCritical.ql
4+
ql/actions/ql/src/Security/CWE-1395/UseOfKnownVulnerableAction.ql
5+
ql/actions/ql/src/Security/CWE-275/MissingActionsPermissions.ql
6+
ql/actions/ql/src/Security/CWE-285/ImproperAccessControl.ql
7+
ql/actions/ql/src/Security/CWE-312/ExcessiveSecretsExposure.ql
8+
ql/actions/ql/src/Security/CWE-312/SecretsInArtifacts.ql
9+
ql/actions/ql/src/Security/CWE-312/UnmaskedSecretExposure.ql
10+
ql/actions/ql/src/Security/CWE-349/CachePoisoningViaCodeInjection.ql
11+
ql/actions/ql/src/Security/CWE-349/CachePoisoningViaDirectCache.ql
12+
ql/actions/ql/src/Security/CWE-349/CachePoisoningViaPoisonableStep.ql
13+
ql/actions/ql/src/Security/CWE-367/UntrustedCheckoutTOCTOUCritical.ql
14+
ql/actions/ql/src/Security/CWE-367/UntrustedCheckoutTOCTOUHigh.ql
15+
ql/actions/ql/src/Security/CWE-829/ArtifactPoisoningCritical.ql
16+
ql/actions/ql/src/Security/CWE-829/UntrustedCheckoutCritical.ql
17+
ql/actions/ql/src/Security/CWE-829/UntrustedCheckoutHigh.ql
Lines changed: 27 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,27 @@
1+
ql/actions/ql/src/Debug/SyntaxError.ql
2+
ql/actions/ql/src/Security/CWE-077/EnvPathInjectionCritical.ql
3+
ql/actions/ql/src/Security/CWE-077/EnvPathInjectionMedium.ql
4+
ql/actions/ql/src/Security/CWE-077/EnvVarInjectionCritical.ql
5+
ql/actions/ql/src/Security/CWE-077/EnvVarInjectionMedium.ql
6+
ql/actions/ql/src/Security/CWE-094/CodeInjectionCritical.ql
7+
ql/actions/ql/src/Security/CWE-094/CodeInjectionMedium.ql
8+
ql/actions/ql/src/Security/CWE-1395/UseOfKnownVulnerableAction.ql
9+
ql/actions/ql/src/Security/CWE-275/MissingActionsPermissions.ql
10+
ql/actions/ql/src/Security/CWE-285/ImproperAccessControl.ql
11+
ql/actions/ql/src/Security/CWE-312/ExcessiveSecretsExposure.ql
12+
ql/actions/ql/src/Security/CWE-312/SecretsInArtifacts.ql
13+
ql/actions/ql/src/Security/CWE-312/UnmaskedSecretExposure.ql
14+
ql/actions/ql/src/Security/CWE-349/CachePoisoningViaCodeInjection.ql
15+
ql/actions/ql/src/Security/CWE-349/CachePoisoningViaDirectCache.ql
16+
ql/actions/ql/src/Security/CWE-349/CachePoisoningViaPoisonableStep.ql
17+
ql/actions/ql/src/Security/CWE-367/UntrustedCheckoutTOCTOUCritical.ql
18+
ql/actions/ql/src/Security/CWE-367/UntrustedCheckoutTOCTOUHigh.ql
19+
ql/actions/ql/src/Security/CWE-571/ExpressionIsAlwaysTrueCritical.ql
20+
ql/actions/ql/src/Security/CWE-571/ExpressionIsAlwaysTrueHigh.ql
21+
ql/actions/ql/src/Security/CWE-829/ArtifactPoisoningCritical.ql
22+
ql/actions/ql/src/Security/CWE-829/ArtifactPoisoningMedium.ql
23+
ql/actions/ql/src/Security/CWE-829/UnpinnedActionsTag.ql
24+
ql/actions/ql/src/Security/CWE-829/UntrustedCheckoutCritical.ql
25+
ql/actions/ql/src/Security/CWE-829/UntrustedCheckoutHigh.ql
26+
ql/actions/ql/src/Security/CWE-829/UntrustedCheckoutMedium.ql
27+
ql/actions/ql/src/Violations Of Best Practice/CodeQL/UnnecessaryUseOfAdvancedConfig.ql
Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
ql/actions/ql/src/Security/CWE-077/EnvPathInjectionCritical.ql
2+
ql/actions/ql/src/Security/CWE-077/EnvPathInjectionMedium.ql
3+
ql/actions/ql/src/Security/CWE-077/EnvVarInjectionCritical.ql
4+
ql/actions/ql/src/Security/CWE-077/EnvVarInjectionMedium.ql
5+
ql/actions/ql/src/Security/CWE-094/CodeInjectionCritical.ql
6+
ql/actions/ql/src/Security/CWE-094/CodeInjectionMedium.ql
7+
ql/actions/ql/src/Security/CWE-1395/UseOfKnownVulnerableAction.ql
8+
ql/actions/ql/src/Security/CWE-275/MissingActionsPermissions.ql
9+
ql/actions/ql/src/Security/CWE-285/ImproperAccessControl.ql
10+
ql/actions/ql/src/Security/CWE-312/ExcessiveSecretsExposure.ql
11+
ql/actions/ql/src/Security/CWE-312/SecretsInArtifacts.ql
12+
ql/actions/ql/src/Security/CWE-312/UnmaskedSecretExposure.ql
13+
ql/actions/ql/src/Security/CWE-349/CachePoisoningViaCodeInjection.ql
14+
ql/actions/ql/src/Security/CWE-349/CachePoisoningViaDirectCache.ql
15+
ql/actions/ql/src/Security/CWE-349/CachePoisoningViaPoisonableStep.ql
16+
ql/actions/ql/src/Security/CWE-367/UntrustedCheckoutTOCTOUCritical.ql
17+
ql/actions/ql/src/Security/CWE-367/UntrustedCheckoutTOCTOUHigh.ql
18+
ql/actions/ql/src/Security/CWE-829/ArtifactPoisoningCritical.ql
19+
ql/actions/ql/src/Security/CWE-829/ArtifactPoisoningMedium.ql
20+
ql/actions/ql/src/Security/CWE-829/UnpinnedActionsTag.ql
21+
ql/actions/ql/src/Security/CWE-829/UntrustedCheckoutCritical.ql
22+
ql/actions/ql/src/Security/CWE-829/UntrustedCheckoutHigh.ql
23+
ql/actions/ql/src/Security/CWE-829/UntrustedCheckoutMedium.ql
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
ql/actions/ql/src/Debug/partial.ql
2+
ql/actions/ql/src/Models/CompositeActionsSinks.ql
3+
ql/actions/ql/src/Models/CompositeActionsSources.ql
4+
ql/actions/ql/src/Models/CompositeActionsSummaries.ql
5+
ql/actions/ql/src/Models/ReusableWorkflowsSinks.ql
6+
ql/actions/ql/src/Models/ReusableWorkflowsSources.ql
7+
ql/actions/ql/src/Models/ReusableWorkflowsSummaries.ql
8+
ql/actions/ql/src/experimental/Security/CWE-074/OutputClobberingHigh.ql
9+
ql/actions/ql/src/experimental/Security/CWE-078/CommandInjectionCritical.ql
10+
ql/actions/ql/src/experimental/Security/CWE-078/CommandInjectionMedium.ql
11+
ql/actions/ql/src/experimental/Security/CWE-088/ArgumentInjectionCritical.ql
12+
ql/actions/ql/src/experimental/Security/CWE-088/ArgumentInjectionMedium.ql
13+
ql/actions/ql/src/experimental/Security/CWE-200/SecretExfiltration.ql
14+
ql/actions/ql/src/experimental/Security/CWE-284/CodeExecutionOnSelfHostedRunner.ql
15+
ql/actions/ql/src/experimental/Security/CWE-829/ArtifactPoisoningPathTraversal.ql
16+
ql/actions/ql/src/experimental/Security/CWE-829/UnversionedImmutableAction.ql
17+
ql/actions/ql/src/experimental/Security/CWE-918/RequestForgery.ql
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
import runs_on
2+
import pytest
3+
from query_suites import *
4+
5+
well_known_query_suites = ['actions-code-quality.qls', 'actions-security-and-quality.qls', 'actions-security-extended.qls', 'actions-code-scanning.qls']
6+
7+
@runs_on.posix
8+
@pytest.mark.parametrize("query_suite", well_known_query_suites)
9+
def test(codeql, actions, check_query_suite, query_suite):
10+
check_query_suite(query_suite)
11+
12+
@runs_on.posix
13+
def test_not_included_queries(codeql, actions, check_queries_not_included):
14+
check_queries_not_included('actions', well_known_query_suites)

actions/ql/lib/CHANGELOG.md

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,13 @@
1-
## 0.4.7
1+
## 0.4.8
22

33
No user-facing changes.
44

5+
## 0.4.7
6+
7+
### New Features
8+
9+
* CodeQL and Copilot Autofix support for GitHub Actions is now Generally Available.
10+
511
## 0.4.6
612

713
### Bug Fixes
Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,5 @@
11
## 0.4.7
22

3-
No user-facing changes.
3+
### New Features
4+
5+
* CodeQL and Copilot Autofix support for GitHub Actions is now Generally Available.
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
## 0.4.8
2+
3+
No user-facing changes.
Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,2 +1,2 @@
11
---
2-
lastReleaseVersion: 0.4.7
2+
lastReleaseVersion: 0.4.8

0 commit comments

Comments
 (0)