Skip to content

Commit 7a1369d

Browse files
author
Alvaro Muñoz
authored
Merge pull request #19 from GitHubSecurityLab/steps
2 parents d6f6e1f + 9e2be7d commit 7a1369d

File tree

39 files changed

+248
-1
lines changed

39 files changed

+248
-1
lines changed
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["akhileshns/heroku-deploy", "*", "input.branch", "output.status", "taint"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["android-actions/setup-android", "*", "input.cmdline-tools-version", "output.ANDROID_COMMANDLINE_TOOLS_VERSION", "taint"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["apple-actions/import-codesign-certs", "*", "input.keychain-password", "output.keychain-password", "taint"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["ashley-taylor/read-json-property-action", "*", "input.json", "output.value", "taint"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["ashley-taylor/regex-property-action", "*", "input.replacement", "output.value", "taint"]
7+
- ["ashley-taylor/regex-property-action", "*", "input.value", "output.value", "taint"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["aszc/change-string-case-action", "*", "input.string", "output.capitalized", "taint"]
7+
- ["aszc/change-string-case-action", "*", "input.replace-with", "output.uppercase", "taint"]
8+
- ["aszc/change-string-case-action", "*", "input.replace-with", "output.lowercase", "taint"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["aws-actions/configure-aws-credentials", "*", "input.aws-access-key-id", "env.AWS_ACCESS_KEY_ID", "taint"]
7+
- ["aws-actions/configure-aws-credentials", "*", "input.aws-access-key-id", "secret.AWS_ACCESS_KEY_ID", "taint"]
8+
- ["aws-actions/configure-aws-credentials", "*", "input.aws-secret-access-key", "env.AWS_SECRET_ACCESS_KEY", "taint"]
9+
- ["aws-actions/configure-aws-credentials", "*", "input.aws-secret-access-key", "secret.AWS_SECRET_ACCESS_KEY", "taint"]
10+
- ["aws-actions/configure-aws-credentials", "*", "input.aws-session-token", "env.AWS_SESSION_TOKEN", "taint"]
11+
- ["aws-actions/configure-aws-credentials", "*", "input.aws-session-token", "secret.AWS_SESSION_TOKEN", "taint"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["bobheadxi/deployments", "*", "input.env", "output.env", "taint"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["bufbuild/buf-breaking-action", "*", "input.buf_token", "env.BUF_TOKEN", "taint"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["bufbuild/buf-lint-action", "*", "input.buf_token", "env.BUF_TOKEN", "taint"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["cachix/cachix-action", "*", "input.signingKey", "env.CACHIX_SIGNING_KEY", "taint"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["coursier/cache-action", "*", "input.path", "env.COURSIER_CACHE", "taint"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["crazy-max/ghaction-import-gpg", "*", "input.fingerprint", "output.fingerprint", "taint"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["csexton/release-asset-action", "*", "input.release-url", "output.url", "taint"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["delaguardo/setup-clojure", "*", "input.boot", "env.BOOT_VERSION", "taint"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: sourceModel
5+
data:
6+
- ["franzdiebold/github-env-vars-action", "*", "output.CI_PR_DESCRIPTION", "pull_request_target", "PR body"]
7+
- ["franzdiebold/github-env-vars-action", "*", "output.CI_PR_TITLE", "pull_request_target", "PR title"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["game-ci/unity-test-runner", "*", "input.artifactsPath", "output.artifactsPath", "taint"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["getsentry/action-release", "*", "input.version", "output.version", "taint"]
7+
- ["getsentry/action-release", "*", "input.version_prefix", "output.version", "taint"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["github/codeql-action", "*", "input.output", "output.sarif-output", "taint"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["gradle/gradle-build-action", "*", "input.cache-encryption-key", "env.GRADLE_ENCRYPTION_KEY", "taint"]
7+
- ["gradle/gradle-build-action", "*", "input.build-scan-terms-of-service-agree", "env.BUILD_SCAN_TERMS_OF_SERVICE_AGREE", "taint"]
8+
- ["gradle/gradle-build-action", "*", "input.build-scan-terms-of-service-url", "env.BUILD_SCAN_TERMS_OF_SERVICE_URL", "taint"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["haya14busa/action-cond", "*", "input.if_true", "output.value", "taint"]
7+
- ["haya14busa/action-cond", "*", "input.if_false", "output.value", "taint"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["hexlet/project-action", "*", "input.mount-path", "env.PWD", "taint"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["jsdaniell/create-json", "*", "input.name", "output.successfully", "taint"]
7+
- ["jsdaniell/create-json", "*", "input.json", "output.successfully", "taint"]
8+
- ["jsdaniell/create-json", "*", "input.dir", "output.successfully", "taint"]
+6
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["jwalton/gh-ecr-push", "*", "input.image", "output.imageUrl", "taint"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: sourceModel
5+
data:
6+
- ["khan/pull-request-comment-trigger", "*", "output.comment_body", "issue_comment", ""]
7+
- ["khan/pull-request-comment-trigger", "*", "output.comment_body", "pull_request_comment", ""]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["larsoner/circleci-artifacts-redirector-action", "*", "input.artifact-path", "output.url", "taint"]

ql/lib/ext/mad9000_actions-find-and-replace-string.model.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -4,4 +4,4 @@ extensions:
44
extensible: summaryModel
55
data:
66
- ["mad9000/actions-find-and-replace-string", "*", "input.source", "output.value", "taint"]
7-
- ["mad9000/actions-find-and-replace-string", "*", "input.replace", "output.value", "taint"]
7+
- ["mad9000/actions-find-and-replace-string", "*", "input.replace", "output.value", "taint"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["mattdavis0351/actions", "*", "input.image-name", "output.imageUrl", "taint"]
7+
- ["mattdavis0351/actions", "*", "input.tag", "output.imageUrl", "taint"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["metro-digital/setup-tools-for-waas", "*", "input.gcp_sa_key", "env.GCLOUD_PROJECT", "taint"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["mishakav/pytest-coverage-comment", "*", "input.multiple-files", "output.summaryReport", "taint"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["mymindstorm/setup-emsdk", "*", "input.actions-cache-folder", "env.EMSDK", "taint"]

ql/lib/ext/ruby_setup-ruby.model.yml

+6
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["ruby/setup-ruby", "*", "input.ruby-version", "output.ruby-prefix", "taint"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["salsify/action-detect-and-tag-new-version", "*", "input.tag-template", "output.tag", "taint"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["shallwefootball/upload-s3-action", "*", "input.destination_dir", "output.object_key", "taint"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["shogo82148/actions-setup-perl", "*", "input.working-directory", "env.PERL5LIB", "taint"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["suisei-cn/actions-download-file", "*", "input.filename", "output.filename", "taint"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: summaryModel
5+
data:
6+
- ["timheuer/base64-to-file", "*", "input.fileName", "output.filePath", "taint"]
7+
- ["timheuer/base64-to-file", "*", "input.fileDir", "output.filePath", "taint"]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: sourceModel
5+
data:
6+
- ["tzkhan/pr-update-action", "*", "output.headMatch", "pull_request_target", ""]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/actions-all
4+
extensible: sourceModel
5+
data:
6+
- ["xt0rted/slash-command-action", "*", "output.command-arguments", "issue_comment", ""]
7+
- ["xt0rted/slash-command-action", "*", "output.command-arguments", "pull_request_comment", ""]

0 commit comments

Comments
 (0)