github / github/codeql

[Actions] CWE-285/ImproperAccessControl.ql Not Currently Working

Abierto
#20,706 4 comentarios 0 reacciones 0 asignados Ver en GitHub
question
Lenguaje dominante
CodeQL
Estrellas
10.1k
Forks
2.1k
Merge medio
2 d 15 h
PR fusionados (30 d)
141

Descripción

**Description of the issue**

The Actions ImproperAccessControl query is not working even for trivial workflows. This is an example from https://github.com/github/codeql/blob/main/actions/ql/src/Security/CWE-285/ImproperAccessControl.md and does not trigger a detection.

```yaml
on:
pull_request_target:
types: [opened, synchronize]

jobs:
test:
runs-on: ubuntu-latest
steps:
- name: Checkout repo for OWNER TEST
uses: actions/checkout@v3
if: contains(github.event.pull_request.labels.*.name, 'safe to test')
with:
ref: ${{ github.event.pull_request.head.sha }}
- run: ./cmd
```

All my attempts to try variations that did trigger a finding also failed. Is this detection enabled as part of the default suite (it appears to be)?

Guía de contribución

Abrir la guía de contribución

Línea de trabajo

Start by reproducing the workflow example from actions/ql/src/Security/CWE-285/ImproperAccessControl.md and inspect the corresponding ImproperAccessControl.ql query. Check whether the query is included in the default suite; done means explaining or correcting why the example produces no finding.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Área
security
Tipo de issue
Error
Dificultad
4/5
Tiempo estimado
3-5 días
Estado de actividad
Estancado
Claridad
Bastante claro
Aptitud para principiantes
35/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.