Minor improvemnts

This commit is contained in:
Alvaro Muñoz
2024-06-13 11:51:15 +02:00
parent ceac1c6392
commit a84c1c4706
2 changed files with 10 additions and 8 deletions

View File

@@ -20,12 +20,13 @@ class DownloadArtifactActionStep extends UntrustedArtifactDownloadStep, UsesStep
DownloadArtifactActionStep() {
this.getCallee() =
[
"dawidd6/action-download-artifact", "marcofaggian/action-download-multiple-artifacts",
"benday-inc/download-latest-artifact", "blablacar/action-download-last-artifact",
"levonet/action-download-last-artifact", "bettermarks/action-artifact-download",
"aochmann/actions-download-artifact", "cytopia/download-artifact-retry-action",
"alextompkins/download-prior-artifact", "nmerget/download-gzip-artifact",
"benday-inc/download-artifact", "synergy-au/download-workflow-artifacts-action",
"actions/download-artifact", "dawidd6/action-download-artifact",
"marcofaggian/action-download-multiple-artifacts", "benday-inc/download-latest-artifact",
"blablacar/action-download-last-artifact", "levonet/action-download-last-artifact",
"bettermarks/action-artifact-download", "aochmann/actions-download-artifact",
"cytopia/download-artifact-retry-action", "alextompkins/download-prior-artifact",
"nmerget/download-gzip-artifact", "benday-inc/download-artifact",
"synergy-au/download-workflow-artifacts-action", "ishworkh/docker-image-artifact-download",
"ishworkh/container-image-artifact-download", "sidx1024/action-download-artifact",
"hyperskill/azblob-download-artifact", "ma-ve/action-download-artifact-with-retry"
] and

View File

@@ -19,10 +19,11 @@ class DangerousActionUsesStep extends PoisonableStep, UsesStep {
private string dangerousCommands() {
result =
[
"npm install", "npm run ", "yarn ", "npm ci(\\b|$)", "make ", "terraform plan",
"npm i(nstall)?(\\b|$)", "npm run ", "yarn ", "npm ci(\\b|$)", "make ", "terraform plan",
"terraform apply", "gomplate ", "pre-commit run", "pre-commit install", "go generate",
"msbuild ", "mvn ", "gradle ", "bundle install", "bundle exec ", "^ant ", "mkdocs build",
"pytest", "pip install -r ", "pip install --requirement", "java -jar "
"pytest", "pip install -r ", "pip install --requirement", "java -jar ", "poetry install",
"poetry run"
]
}