Update CWE-829 description for clarity

This commit is contained in:
Marco Gario
2025-03-26 15:53:20 +01:00
committed by GitHub
parent b1737858fa
commit 288fcb6092

View File

@@ -1,5 +1,5 @@
/**
* @name Checkout of untrusted code in trusted context with poisonable step
* @name Checkout of untrusted code in priviledged context
* @description Privileged workflows have read/write access to the base repository and access to secrets.
* By explicitly checking out and running the build script from a fork the untrusted code is running in an environment
* that is able to push to the base repository and to access secrets.