mirror of
https://github.com/github/codeql.git
synced 2025-12-16 16:53:25 +01:00
Actions/SecretExfiltrationQuery
actions/ql/src/experimental/Security/CWE-200/SecretExfiltration.ql uses source as endpoint
This commit is contained in:
@@ -17,8 +17,6 @@ private module SecretExfiltrationConfig implements DataFlow::ConfigSig {
|
|||||||
predicate isSink(DataFlow::Node sink) { sink instanceof SecretExfiltrationSink }
|
predicate isSink(DataFlow::Node sink) { sink instanceof SecretExfiltrationSink }
|
||||||
|
|
||||||
predicate observeDiffInformedIncrementalMode() { any() }
|
predicate observeDiffInformedIncrementalMode() { any() }
|
||||||
|
|
||||||
Location getASelectedSourceLocation(DataFlow::Node sink) { none() }
|
|
||||||
}
|
}
|
||||||
|
|
||||||
/** Tracks flow of unsafe user input that is used in a context where it may lead to a secret exfiltration. */
|
/** Tracks flow of unsafe user input that is used in a context where it may lead to a secret exfiltration. */
|
||||||
|
|||||||
Reference in New Issue
Block a user