CodeQL library for GitHub Actions
codeql/actions-all 0.4.27-dev (changelog, source)
Search

Predicate untrustedGhCommandDataModel

Holds for gh commands that may introduce untrusted data

Import path

import codeql.actions.config.ConfigExtensions
predicate untrustedGhCommandDataModel(string cmd_regex, string flag)