diff --git a/.github/action/dist/index.js b/.github/action/dist/index.js index e13da63ecda..23c03588162 100644 --- a/.github/action/dist/index.js +++ b/.github/action/dist/index.js @@ -28606,7 +28606,7 @@ async function newCodeQL() { return { language: "yaml", path: await findCodeQL(), - pack: "GitHubSecurityLab/actions-queries", + pack: "githubsecuritylab/actions-queries", suite: "codeql-suites/actions-code-scanning.qls", source_root: core.getInput("source-root"), output: core.getInput("sarif"), diff --git a/.github/action/src/codeql.ts b/.github/action/src/codeql.ts index eeeef401a52..3826737a082 100644 --- a/.github/action/src/codeql.ts +++ b/.github/action/src/codeql.ts @@ -25,7 +25,7 @@ export async function newCodeQL(): Promise { return { language: "yaml", path: await findCodeQL(), - pack: "GitHubSecurityLab/actions-queries", + pack: "githubsecuritylab/actions-queries", suite: "codeql-suites/actions-code-scanning.qls", source_root: core.getInput("source-root"), output: core.getInput("sarif"), diff --git a/ql/lib/qlpack.yml b/ql/lib/qlpack.yml index dc4daebaac8..1ccfae0b278 100644 --- a/ql/lib/qlpack.yml +++ b/ql/lib/qlpack.yml @@ -1,7 +1,7 @@ --- library: true warnOnImplicitThis: true -name: GitHubSecurityLab/actions-all +name: githubsecuritylab/actions-all version: 0.0.1-dev dependencies: codeql/controlflow: ^0.1.7 diff --git a/ql/src/codeql-suites/actions-code-scanning.qls b/ql/src/codeql-suites/actions-code-scanning.qls index e69de29bb2d..7d6c94e0c8c 100644 --- a/ql/src/codeql-suites/actions-code-scanning.qls +++ b/ql/src/codeql-suites/actions-code-scanning.qls @@ -0,0 +1,19 @@ +- description: Standard Code Scanning queries for Actions +- queries: . + +- include: + kind: + - problem + - path-problem + tags contain: + - security + - maintainability + +- include: + kind: + - diagnostic + +- exclude: + tags contain: + - experimental + - testing diff --git a/ql/src/qlpack.yml b/ql/src/qlpack.yml index 919a244b390..fb5d29fb957 100644 --- a/ql/src/qlpack.yml +++ b/ql/src/qlpack.yml @@ -1,6 +1,6 @@ --- library: false -name: GitHubSecurityLab/actions-queries +name: githubsecuritylab/actions-queries version: 0.0.1 groups: - actions