We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 38f0077 commit a9c4d6fCopy full SHA for a9c4d6f
actions/ql/lib/codeql/actions/security/ArtifactPoisoningQuery.qll
@@ -264,7 +264,7 @@ class ArtifactPoisoningSink extends DataFlow::Node {
264
download.getAFollowingStep() = poisonable and
265
// excluding artifacts downloaded to /tmp and runner.tmp
266
not download.getPath().regexpMatch("^/tmp.*") and
267
- not download.getPath().regexpMatch("^\${{\s?runner.temp\s?}}.*") and
+ not download.getPath().regexpMatch("^\\${{\\s?runner.temp\\s?}}.*") and
268
(
269
poisonable.(Run).getScript() = this.asExpr() and
270
0 commit comments