Files
codeql/ql/lib/ext/blackducksoftware_github-action.model.yml
2024-04-11 11:24:42 +02:00

9 lines
410 B
YAML

extensions:
- addsTo:
pack: githubsecuritylab/actions-all
extensible: sinkModel
data:
- ["blackducksoftware/github-action", "*", "input.args", "command-injection", "manual"]
- ["blackducksoftware/github-action", "*", "input.blackduck.url", "command-injection", "manual"]
- ["blackducksoftware/github-action", "*", "input.blackduck.api.token", "command-injection", "manual"]