Skip to content

Commit a84c1c4

Browse files
author
Alvaro Muñoz
committed
Minor improvemnts
1 parent ceac1c6 commit a84c1c4

File tree

2 files changed

+10
-8
lines changed

2 files changed

+10
-8
lines changed

ql/lib/codeql/actions/security/ArtifactPoisoningQuery.qll

Lines changed: 7 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -20,12 +20,13 @@ class DownloadArtifactActionStep extends UntrustedArtifactDownloadStep, UsesStep
2020
DownloadArtifactActionStep() {
2121
this.getCallee() =
2222
[
23-
"dawidd6/action-download-artifact", "marcofaggian/action-download-multiple-artifacts",
24-
"benday-inc/download-latest-artifact", "blablacar/action-download-last-artifact",
25-
"levonet/action-download-last-artifact", "bettermarks/action-artifact-download",
26-
"aochmann/actions-download-artifact", "cytopia/download-artifact-retry-action",
27-
"alextompkins/download-prior-artifact", "nmerget/download-gzip-artifact",
28-
"benday-inc/download-artifact", "synergy-au/download-workflow-artifacts-action",
23+
"actions/download-artifact", "dawidd6/action-download-artifact",
24+
"marcofaggian/action-download-multiple-artifacts", "benday-inc/download-latest-artifact",
25+
"blablacar/action-download-last-artifact", "levonet/action-download-last-artifact",
26+
"bettermarks/action-artifact-download", "aochmann/actions-download-artifact",
27+
"cytopia/download-artifact-retry-action", "alextompkins/download-prior-artifact",
28+
"nmerget/download-gzip-artifact", "benday-inc/download-artifact",
29+
"synergy-au/download-workflow-artifacts-action", "ishworkh/docker-image-artifact-download",
2930
"ishworkh/container-image-artifact-download", "sidx1024/action-download-artifact",
3031
"hyperskill/azblob-download-artifact", "ma-ve/action-download-artifact-with-retry"
3132
] and

ql/lib/codeql/actions/security/PoisonableSteps.qll

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -19,10 +19,11 @@ class DangerousActionUsesStep extends PoisonableStep, UsesStep {
1919
private string dangerousCommands() {
2020
result =
2121
[
22-
"npm install", "npm run ", "yarn ", "npm ci(\\b|$)", "make ", "terraform plan",
22+
"npm i(nstall)?(\\b|$)", "npm run ", "yarn ", "npm ci(\\b|$)", "make ", "terraform plan",
2323
"terraform apply", "gomplate ", "pre-commit run", "pre-commit install", "go generate",
2424
"msbuild ", "mvn ", "gradle ", "bundle install", "bundle exec ", "^ant ", "mkdocs build",
25-
"pytest", "pip install -r ", "pip install --requirement", "java -jar "
25+
"pytest", "pip install -r ", "pip install --requirement", "java -jar ", "poetry install",
26+
"poetry run"
2627
]
2728
}
2829

0 commit comments

Comments
 (0)