Skip to content

Commit abd49d5

Browse files
author
Alvaro Muñoz
committed
Improve privilege workflow detection
1 parent fe06c9e commit abd49d5

File tree

1 file changed

+0
-16
lines changed

1 file changed

+0
-16
lines changed

ql/lib/codeql/actions/Helper.qll

Lines changed: 0 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -252,26 +252,10 @@ predicate inPrivilegedExternallyTriggerableJob(AstNode node) {
252252
)
253253
}
254254

255-
predicate calledByPrivilegedExternallyTriggerableJob(AstNode node) {
256-
exists(ReusableWorkflow rw, ExternalJob caller, Job callee |
257-
callee = node.getEnclosingJob() and
258-
rw.getACaller() = caller and
259-
rw.getAJob() = callee and
260-
caller.isPrivilegedExternallyTriggerable()
261-
)
262-
or
263-
exists(LocalJob caller |
264-
caller = node.getEnclosingCompositeAction().getACallerJob() and
265-
caller.isPrivilegedExternallyTriggerable()
266-
)
267-
}
268-
269255
predicate inPrivilegedContext(AstNode node) {
270256
inPrivilegedCompositeAction(node)
271257
or
272258
inPrivilegedExternallyTriggerableJob(node)
273-
or
274-
calledByPrivilegedExternallyTriggerableJob(node)
275259
}
276260

277261
predicate inNonPrivilegedCompositeAction(AstNode node) {

0 commit comments

Comments
 (0)