We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 4f62573 commit ae6856aCopy full SHA for ae6856a
ql/lib/codeql/actions/security/ControlChecks.qll
@@ -267,6 +267,13 @@ class AssociationActionCheck extends AssociationCheck instanceof UsesStep {
267
268
class PermissionActionCheck extends PermissionCheck instanceof UsesStep {
269
PermissionActionCheck() {
270
+ this.getCallee() = "actions-cool/check-user-permission" and
271
+ (
272
+ // default permission level is write
273
+ not exists(this.getArgument("permission-level")) or
274
+ this.getArgument("require") = ["write", "admin"]
275
+ )
276
+ or
277
this.getCallee() = "sushichop/action-repository-permission" and
278
this.getArgument("required-permission") = ["write", "admin"]
279
or
0 commit comments