Add option to generate code excution commands/steps
Open
feature
Low Priority
query-library
- Dominant language
- Python
- Stars
- 747
- Forks
- 45
- PR merge metrics
- No merged PRs in 30d
Description
This is supposed to be fuctinality added to report sub-command.
After quering neo4j and finding vulnerable workflows or actions, it should print an explanation about the exploit, and how it could be exploited - for example -
"Command injection through PR name is possible in this workflow -
`PR NAME = 'foo";{bash_command} "'`
Contributor guide
Assessment
This issue has not been assessed yet.