Skip to content

Commit f4f9196

Browse files
AdnaneKhanJarLob
andauthored
Correctly specify regex.
Co-authored-by: Jaroslav Lobačevski <[email protected]>
1 parent aca3d89 commit f4f9196

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

actions/ql/lib/codeql/actions/security/ArtifactPoisoningQuery.qll

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -264,7 +264,7 @@ class ArtifactPoisoningSink extends DataFlow::Node {
264264
download.getAFollowingStep() = poisonable and
265265
// excluding artifacts downloaded to /tmp and runner.tmp
266266
not download.getPath().regexpMatch("^/tmp.*") and
267-
not download.getPath().regexpMatch("^\\${{\\s?runner.temp\\s?}}.*") and
267+
not download.getPath().regexpMatch("^\\$\\{\\{\\s?runner\\.temp\\s?}}.*") and
268268
(
269269
poisonable.(Run).getScript() = this.asExpr() and
270270
(

0 commit comments

Comments
 (0)