Files
codeql/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/actions.js

6 lines
127 B
JavaScript

const github = require('@actions/github');
function test() {
eval(github.context.payload.commits[1].message); // NOT OK
}