|
1 | 1 | nodes
|
2 |
| -| actions.js:3:6:3:16 | process.env | |
3 |
| -| actions.js:3:6:3:16 | process.env | |
4 |
| -| actions.js:3:6:3:29 | process ... _DATA'] | |
5 |
| -| actions.js:3:6:3:29 | process ... _DATA'] | |
6 |
| -| actions.js:6:15:6:15 | e | |
7 |
| -| actions.js:7:10:7:10 | e | |
8 |
| -| actions.js:7:10:7:23 | e['TEST_DATA'] | |
9 |
| -| actions.js:7:10:7:23 | e['TEST_DATA'] | |
10 |
| -| actions.js:11:6:11:16 | process.env | |
11 |
| -| actions.js:11:6:11:16 | process.env | |
| 2 | +| actions.js:4:6:4:16 | process.env | |
| 3 | +| actions.js:4:6:4:16 | process.env | |
| 4 | +| actions.js:4:6:4:29 | process ... _DATA'] | |
| 5 | +| actions.js:4:6:4:29 | process ... _DATA'] | |
| 6 | +| actions.js:7:15:7:15 | e | |
| 7 | +| actions.js:8:10:8:10 | e | |
| 8 | +| actions.js:8:10:8:23 | e['TEST_DATA'] | |
| 9 | +| actions.js:8:10:8:23 | e['TEST_DATA'] | |
| 10 | +| actions.js:12:6:12:16 | process.env | |
| 11 | +| actions.js:12:6:12:16 | process.env | |
| 12 | +| actions.js:14:6:14:21 | getInput('data') | |
| 13 | +| actions.js:14:6:14:21 | getInput('data') | |
| 14 | +| actions.js:14:6:14:21 | getInput('data') | |
12 | 15 | | command-line-parameter-command-injection.js:4:10:4:21 | process.argv |
|
13 | 16 | | command-line-parameter-command-injection.js:4:10:4:21 | process.argv |
|
14 | 17 | | command-line-parameter-command-injection.js:4:10:4:21 | process.argv |
|
@@ -222,15 +225,16 @@ nodes
|
222 | 225 | | command-line-parameter-command-injection.js:146:22:146:38 | program.pizzaType |
|
223 | 226 | | command-line-parameter-command-injection.js:146:22:146:38 | program.pizzaType |
|
224 | 227 | edges
|
225 |
| -| actions.js:3:6:3:16 | process.env | actions.js:3:6:3:29 | process ... _DATA'] | |
226 |
| -| actions.js:3:6:3:16 | process.env | actions.js:3:6:3:29 | process ... _DATA'] | |
227 |
| -| actions.js:3:6:3:16 | process.env | actions.js:3:6:3:29 | process ... _DATA'] | |
228 |
| -| actions.js:3:6:3:16 | process.env | actions.js:3:6:3:29 | process ... _DATA'] | |
229 |
| -| actions.js:6:15:6:15 | e | actions.js:7:10:7:10 | e | |
230 |
| -| actions.js:7:10:7:10 | e | actions.js:7:10:7:23 | e['TEST_DATA'] | |
231 |
| -| actions.js:7:10:7:10 | e | actions.js:7:10:7:23 | e['TEST_DATA'] | |
232 |
| -| actions.js:11:6:11:16 | process.env | actions.js:6:15:6:15 | e | |
233 |
| -| actions.js:11:6:11:16 | process.env | actions.js:6:15:6:15 | e | |
| 228 | +| actions.js:4:6:4:16 | process.env | actions.js:4:6:4:29 | process ... _DATA'] | |
| 229 | +| actions.js:4:6:4:16 | process.env | actions.js:4:6:4:29 | process ... _DATA'] | |
| 230 | +| actions.js:4:6:4:16 | process.env | actions.js:4:6:4:29 | process ... _DATA'] | |
| 231 | +| actions.js:4:6:4:16 | process.env | actions.js:4:6:4:29 | process ... _DATA'] | |
| 232 | +| actions.js:7:15:7:15 | e | actions.js:8:10:8:10 | e | |
| 233 | +| actions.js:8:10:8:10 | e | actions.js:8:10:8:23 | e['TEST_DATA'] | |
| 234 | +| actions.js:8:10:8:10 | e | actions.js:8:10:8:23 | e['TEST_DATA'] | |
| 235 | +| actions.js:12:6:12:16 | process.env | actions.js:7:15:7:15 | e | |
| 236 | +| actions.js:12:6:12:16 | process.env | actions.js:7:15:7:15 | e | |
| 237 | +| actions.js:14:6:14:21 | getInput('data') | actions.js:14:6:14:21 | getInput('data') | |
234 | 238 | | command-line-parameter-command-injection.js:4:10:4:21 | process.argv | command-line-parameter-command-injection.js:4:10:4:21 | process.argv |
|
235 | 239 | | command-line-parameter-command-injection.js:8:22:8:33 | process.argv | command-line-parameter-command-injection.js:8:22:8:36 | process.argv[2] |
|
236 | 240 | | command-line-parameter-command-injection.js:8:22:8:33 | process.argv | command-line-parameter-command-injection.js:8:22:8:36 | process.argv[2] |
|
@@ -419,8 +423,9 @@ edges
|
419 | 423 | | command-line-parameter-command-injection.js:146:22:146:38 | program.pizzaType | command-line-parameter-command-injection.js:146:10:146:38 | "cmd.sh ... zzaType |
|
420 | 424 | | command-line-parameter-command-injection.js:146:22:146:38 | program.pizzaType | command-line-parameter-command-injection.js:146:10:146:38 | "cmd.sh ... zzaType |
|
421 | 425 | #select
|
422 |
| -| actions.js:3:6:3:29 | process ... _DATA'] | actions.js:3:6:3:16 | process.env | actions.js:3:6:3:29 | process ... _DATA'] | This command depends on an unsanitized $@. | actions.js:3:6:3:16 | process.env | environment variable | |
423 |
| -| actions.js:7:10:7:23 | e['TEST_DATA'] | actions.js:11:6:11:16 | process.env | actions.js:7:10:7:23 | e['TEST_DATA'] | This command depends on an unsanitized $@. | actions.js:11:6:11:16 | process.env | environment variable | |
| 426 | +| actions.js:4:6:4:29 | process ... _DATA'] | actions.js:4:6:4:16 | process.env | actions.js:4:6:4:29 | process ... _DATA'] | This command depends on an unsanitized $@. | actions.js:4:6:4:16 | process.env | environment variable | |
| 427 | +| actions.js:8:10:8:23 | e['TEST_DATA'] | actions.js:12:6:12:16 | process.env | actions.js:8:10:8:23 | e['TEST_DATA'] | This command depends on an unsanitized $@. | actions.js:12:6:12:16 | process.env | environment variable | |
| 428 | +| actions.js:14:6:14:21 | getInput('data') | actions.js:14:6:14:21 | getInput('data') | actions.js:14:6:14:21 | getInput('data') | This command depends on an unsanitized $@. | actions.js:14:6:14:21 | getInput('data') | GitHub Actions user input | |
424 | 429 | | command-line-parameter-command-injection.js:4:10:4:21 | process.argv | command-line-parameter-command-injection.js:4:10:4:21 | process.argv | command-line-parameter-command-injection.js:4:10:4:21 | process.argv | This command depends on an unsanitized $@. | command-line-parameter-command-injection.js:4:10:4:21 | process.argv | command-line argument |
|
425 | 430 | | command-line-parameter-command-injection.js:8:10:8:36 | "cmd.sh ... argv[2] | command-line-parameter-command-injection.js:8:22:8:33 | process.argv | command-line-parameter-command-injection.js:8:10:8:36 | "cmd.sh ... argv[2] | This command depends on an unsanitized $@. | command-line-parameter-command-injection.js:8:22:8:33 | process.argv | command-line argument |
|
426 | 431 | | command-line-parameter-command-injection.js:11:14:11:20 | args[0] | command-line-parameter-command-injection.js:10:13:10:24 | process.argv | command-line-parameter-command-injection.js:11:14:11:20 | args[0] | This command depends on an unsanitized $@. | command-line-parameter-command-injection.js:10:13:10:24 | process.argv | command-line argument |
|
|
0 commit comments