Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Actions: Fix version range for known vulnerable actions #18560

Open
wants to merge 4 commits into
base: main
Choose a base branch
from

Conversation

JarLob
Copy link
Contributor

@JarLob JarLob commented Jan 22, 2025

Pull Request checklist

All query authors

Internal query authors only

  • Autofixes generated based on these changes are valid, only needed if this PR makes significant changes to .ql, .qll, or .qhelp files. See the documentation (internal access required).
  • Changes are validated at scale (internal access required).
  • Adding a new query? Consider also adding the query to autofix.

@Copilot Copilot bot review requested due to automatic review settings January 22, 2025 13:56
@JarLob JarLob requested a review from a team as a code owner January 22, 2025 13:56
@github-actions github-actions bot added documentation Actions Analysis of GitHub Actions labels Jan 22, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot reviewed 4 out of 5 changed files in this pull request and generated no comments.

Files not reviewed (1)
  • actions/ql/test/query-tests/Security/CWE-1395/UseOfKnownVulnerableAction.expected: Language not supported

Tip: Copilot only keeps its highest confidence comments to reduce noise and keep you focused. Learn more

@JarLob JarLob changed the title Fixed version range for known vulnerable actions Actions: Fix version range for known vulnerable actions Jan 22, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Actions Analysis of GitHub Actions documentation
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant