Files
codeql/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/actions.js
2025-02-28 13:27:28 +01:00

6 lines
147 B
JavaScript

const github = require('@actions/github');
function test() {
eval(github.context.payload.commits[1].message); // $ Alert[js/code-injection]
}