Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Commit cb9b01c

Browse files
committed
JS: Port new sources based on comment from JarLob
1 parent 3d208c0 commit cb9b01c

1 file changed

Lines changed: 4 additions & 2 deletions

File tree

javascript/ql/lib/semmle/javascript/frameworks/ActionsLib.qll

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -26,11 +26,13 @@ private API::Node taintSource() {
2626
or
2727
result = payload().getMember(["review", "review_comment", "comment"]).getMember("body")
2828
or
29-
result = workflowRun().getMember("head_branch")
29+
result = workflowRun().getMember(["head_branch", "display_title"])
30+
or
31+
result = workflowRun().getMember("head_repository").getMember("description")
3032
or
3133
result = commitObj().getMember("message")
3234
or
33-
result = commitObj().getMember("author").getMember(["name", "email"])
35+
result = commitObj().getMember(["author", "committer"]).getMember(["name", "email"])
3436
}
3537

3638
private class GitHubActionsSource extends RemoteFlowSource {

0 commit comments

Comments
 (0)