Skip to content

Improve actions/ql/src/Security/CWE-829/UntrustedCheckoutX queries further iteration#21852

Draft
knewbury01 wants to merge 5 commits into
github:mainfrom
knewbury01:knewbury01/adjust-actions-queries-untrusted-checkout-second-iteration
Draft

Improve actions/ql/src/Security/CWE-829/UntrustedCheckoutX queries further iteration#21852
knewbury01 wants to merge 5 commits into
github:mainfrom
knewbury01:knewbury01/adjust-actions-queries-untrusted-checkout-second-iteration

Conversation

@knewbury01
Copy link
Copy Markdown
Contributor

@knewbury01 knewbury01 commented May 14, 2026

WIP please do not review yet

changes:

  • reverted name change in previous PR - received feedback that newer version was less clear
  • added more resources to all 3 helpfiles, and added 1 line in recommendations that mentions to check job level permissions
  • improves alert message for high and critical query

@github-actions github-actions Bot added documentation Actions Analysis of GitHub Actions labels May 14, 2026
Comment thread actions/ql/src/Security/CWE-829/UntrustedCheckoutCritical.ql Fixed
Comment thread actions/ql/src/Security/CWE-829/UntrustedCheckoutHigh.ql Fixed
@knewbury01 knewbury01 changed the title Adjust untrusted checkout actions queries Improve actions/ql/src/Security/CWE-829/UntrustedCheckoutX queries second iteration May 14, 2026
@knewbury01 knewbury01 changed the title Improve actions/ql/src/Security/CWE-829/UntrustedCheckoutX queries second iteration Improve actions/ql/src/Security/CWE-829/UntrustedCheckoutX queries further iteration May 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Actions Analysis of GitHub Actions documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants