Commit 55d16e8
committed
Remove false-positive
The `allowed-endpoints` input only flows to `execFileSync("echo", [content])`
(no shell) and `fs.writeFileSync` (JSON config), neither of which is a
command injection vector.
Fixes #21568command-injection sink model for step-security/harden-runner
1 parent 72534e8 commit 55d16e8
File tree
1 file changed
+0
-6
lines changed- actions/ql/lib/ext/manual
1 file changed
+0
-6
lines changedLines changed: 0 additions & 6 deletions
This file was deleted.
0 commit comments