Files
codeql/ql/lib/ext/blackducksoftware_github-action.model.yml
2024-03-14 21:52:22 +01:00

9 lines
380 B
YAML

extensions:
- addsTo:
pack: githubsecuritylab/actions-all
extensible: sinkModel
data:
- ["blackducksoftware/github-action", "*", "input.args", "command-injection"]
- ["blackducksoftware/github-action", "*", "input.blackduck.url", "command-injection"]
- ["blackducksoftware/github-action", "*", "input.blackduck.api.token", "command-injection"]