mirror of
https://github.com/github/codeql.git
synced 2025-12-28 06:36:33 +01:00
ExcessiveSecretsExposure: Reports when all secrets are passed to the workflow runner since that violates the principle of least privelege. UnmaskedSecretExposure: Reports when secrets are derived from a JSON secret since they wont get masked by the workflow runner