-
Notifications
You must be signed in to change notification settings - Fork 2k
Pull requests: github/codeql
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
Actions: Removed a false positive injection sink model for theAnalysis of GitHub Actions
documentation
veracode/veracode-sca action.
Actions
#21604
opened Mar 27, 2026 by
XinyuZhangXvX
Loading…
Add Microsoft to trusted actions owner
Actions
Analysis of GitHub Actions
documentation
#19450
opened May 1, 2025 by
felickz
Contributor
Loading…
Actions: Add workflow_dispatch and workflow_call input sources for code injection
Actions
Analysis of GitHub Actions
documentation
#21660
opened Apr 6, 2026 by
tspascoal
Contributor
Loading…
Actions: Update reference link
Actions
Analysis of GitHub Actions
documentation
#21295
opened Feb 8, 2026 by
thatrobotdev
Loading…
Actions: improve improper access control query
Actions
Analysis of GitHub Actions
documentation
#20904
opened Nov 25, 2025 by
redsun82
Contributor
Loading…
Actions: Add taint summary for suisei-cn/actions-download-file url input
Actions
Analysis of GitHub Actions
documentation
#21600
opened Mar 27, 2026 by
XinyuZhangXvX
Loading…
Actions: Add experimental queries for AI output validation CWE 1426
Actions
Analysis of GitHub Actions
documentation
#21678
opened Apr 9, 2026 by
data-douser
Contributor
•
Draft
Actions: Add experimental prompt injection queries for CWE 1427
Actions
Analysis of GitHub Actions
documentation
#21675
opened Apr 9, 2026 by
data-douser
Contributor
•
Draft
Actions: Add new query Analysis of GitHub Actions
documentation
actions/code-injection/low for code injection with step outputs
Actions
#20974
opened Dec 5, 2025 by
owen-mc
Contributor
Loading…
Actions: Add four experimental queries
Actions
Analysis of GitHub Actions
documentation
#21624
opened Mar 31, 2026 by
JamieMagee
Loading…
ProTip!
What’s not been updated in a month: updated:<2026-03-30.