Are the Actions model files in ext/manual and ext/generated actively used and maintained?
- Dominant language
- CodeQL
- Stars
- 10.1k
- Forks
- 2.1k
- Avg merge
- 2d 15h
- Merged PRs (30d)
- 141
Description
The model files under [actions/ql/lib/ext/manual/](https://github.com/github/codeql/tree/main/actions/ql/lib/ext/manual) and [actions/ql/lib/ext/generated/](https://github.com/github/codeql/tree/main/actions/ql/lib/ext/generated) define threat models for various GitHub Actions. Are these models used by any non-experimental queries? Why haven't these models been updated in ~2 years?
Contributor guide
Research direction
Start by reviewing the model files under actions/ql/lib/ext/manual/ and actions/ql/lib/ext/generated/. Determine whether non-experimental queries use these GitHub Actions models and investigate why they have not been updated in about two years; the work is done when their usage and maintenance status are documented.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions
- Domain
- security
- Issue type
- Documentation
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100