Skip to content

Commit 55d16e8

Browse files
committed
Remove false-positive command-injection sink model for step-security/harden-runner
The `allowed-endpoints` input only flows to `execFileSync("echo", [content])` (no shell) and `fs.writeFileSync` (JSON config), neither of which is a command injection vector. Fixes #21568
1 parent 72534e8 commit 55d16e8

File tree

1 file changed

+0
-6
lines changed

1 file changed

+0
-6
lines changed

actions/ql/lib/ext/manual/step-security_harden-runner.model.yml

Lines changed: 0 additions & 6 deletions
This file was deleted.

0 commit comments

Comments
 (0)