We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
examples
1 parent a5d9cb1 commit 3cdca25Copy full SHA for 3cdca25
actions/ql/examples/codeql-pack.lock.yml
@@ -0,0 +1,4 @@
1
+---
2
+lockVersion: 1.0.0
3
+dependencies: {}
4
+compiled: false
actions/ql/examples/qlpack.yml
@@ -0,0 +1,7 @@
+name: codeql/actions-examples
+groups:
+ - actions
+ - examples
5
+dependencies:
6
+ codeql/actions-all: ${workspace}
7
+warnOnImplicitThis: true
actions/ql/examples/snippets/uses_pinned_sha.ql
@@ -0,0 +1,12 @@
+/**
+ * @name Uses step with pinned SHA
+ * @description Finds 'uses' steps where the version is a pinned SHA.
+ * @id actions/examples/uses-pinned-sha
+ * @tags example
+ */
+
8
+import actions
9
10
+from UsesStep uses
11
+where uses.getVersion().regexpMatch("^[A-Fa-f0-9]{40}$")
12
+select uses, "This 'uses' step has a pinned SHA version."
0 commit comments