Skip to content

Commit e726f9f

Browse files
Alvaro MuñozJarLob
andauthored
Apply suggestions from code review
Co-authored-by: Jaroslav Lobačevski <[email protected]>
1 parent aa37339 commit e726f9f

File tree

1 file changed

+20
-0
lines changed

1 file changed

+20
-0
lines changed

ql/src/Security/CWE-829/UntrustedCheckout.ql

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -48,6 +48,26 @@ predicate containsHeadRef(string s) {
4848
"\\bgithub\\.event\\.workflow_run\\.head_commit\\.id\\b", // The SHA of the head commit.
4949
"\\bgithub\\.event\\.workflow_run\\.head_sha\\b", // The SHA of the head commit.
5050
"\\benv\\.GITHUB_HEAD_REF\\b",
51+
52+
"\\bgithub\\.event\\.check_suite\\.after\\b",
53+
"\\bgithub\\.event\\.check_suite\\.head_sha\\b",
54+
"\\bgithub\\.event\\.check_suite\\.pull_requests\\[\\d+\\]\\.head\\.ref\\b",
55+
"\\bgithub\\.event\\.check_suite\\.pull_requests\\[\\d+\\]\\.head\\.sha\\b",
56+
"\\bgithub\\.event\\.check_suite\\.pull_requests\\[\\d+\\]\\.id\\b",
57+
"\\bgithub\\.event\\.check_suite\\.pull_requests\\[\\d+\\]\\.number\\b",
58+
59+
"\\bgithub\\.event\\.check_run\\.check_suite\\.after\\b",
60+
"\\bgithub\\.event\\.check_run\\.check_suite\\.head_sha\\b",
61+
"\\bgithub\\.event\\.check_run\\.check_suite\\.pull_requests\\[\\d+\\]\\.head\\.ref\\b",
62+
"\\bgithub\\.event\\.check_run\\.check_suite\\.pull_requests\\[\\d+\\]\\.head\\.sha\\b",
63+
"\\bgithub\\.event\\.check_run\\.check_suite\\.pull_requests\\[\\d+\\]\\.id\\b",
64+
"\\bgithub\\.event\\.check_run\\.check_suite\\.pull_requests\\[\\d+\\]\\.number\\b",
65+
66+
"\\bgithub\\.event\\.check_run\\.head_sha\\b",
67+
"\\bgithub\\.event\\.check_run\\.pull_requests\\[\\d+\\]\\.head\\.ref\\b",
68+
"\\bgithub\\.event\\.check_run\\.pull_requests\\[\\d+\\]\\.head\\.sha\\b",
69+
"\\bgithub\\.event\\.check_run\\.pull_requests\\[\\d+\\]\\.id\\b",
70+
"\\bgithub\\.event\\.check_run\\.pull_requests\\[\\d+\\]\\.number\\b",
5171
], _, _)
5272
)
5373
}

0 commit comments

Comments
 (0)