|
1 | | -consistencyOverview |
2 | | -| multipleSuccessors | 17 | |
3 | | -multipleSuccessors |
4 | | -| .github/workflows/arg_injection.yml:10:15:10:50 | github.event.pull_request.title | successor | .github/workflows/arg_injection.yml:15:17:15:57 | github.event.pull_request.head.ref | |
5 | | -| .github/workflows/arg_injection.yml:10:15:10:50 | github.event.pull_request.title | successor | .github/workflows/arg_injection.yml:16:14:18:32 | # NOT VULNERABLE\necho "s/FOO/$TITLE/g"\n | |
6 | | -| .github/workflows/arg_injection.yml:10:15:10:50 | github.event.pull_request.title | successor | .github/workflows/arg_injection.yml:19:14:21:31 | # VULNERABLE\nsed "s/FOO/$TITLE/g"\n | |
7 | | -| .github/workflows/arg_injection.yml:10:15:10:50 | github.event.pull_request.title | successor | .github/workflows/arg_injection.yml:22:14:24:50 | # VULNERABLE\necho "foo" \| sed "s/FOO/$TITLE/g" > bar\n | |
8 | | -| .github/workflows/arg_injection.yml:10:15:10:50 | github.event.pull_request.title | successor | .github/workflows/arg_injection.yml:25:14:27:58 | # VULNERABLE\necho $(echo "foo" \| sed "s/FOO/$TITLE/g" > bar)\n | |
9 | | -| .github/workflows/arg_injection.yml:10:15:10:50 | github.event.pull_request.title | successor | .github/workflows/arg_injection.yml:28:14:30:31 | # VULNERABLE\nawk "BEGIN {$TITLE}"\n | |
10 | | -| .github/workflows/arg_injection.yml:10:15:10:50 | github.event.pull_request.title | successor | .github/workflows/arg_injection.yml:31:14:33:84 | # VULNERABLE\nsed -i "s/git_branch = .*/git_branch = \\"$GITHUB_HEAD_REF\\"/" config.json\n | |
11 | | -| .github/workflows/arg_injection.yml:10:15:10:50 | github.event.pull_request.title | successor | .github/workflows/arg_injection.yml:34:14:36:84 | # VULNERABLE\nsed -i "s\|git_branch = .*\|git_branch = \\"$GITHUB_HEAD_REF\\"\|" config.json\n | |
12 | | -| .github/workflows/arg_injection.yml:10:15:10:50 | github.event.pull_request.title | successor | .github/workflows/arg_injection.yml:37:14:42:111 | # VULNERABLE\nsed -e 's#<branch_to_sync>#${TITLE}#' \\\n -e 's#<sot_repo>#${{ env.sot_repo }}#' \\\n -e 's#<destination_repo>#TITLE#' \\\n .github/workflows/common-copybara.bara.sky.template > .github/workflows/common-copybara.bara.sky\n | |
13 | | -| .github/workflows/arg_injection.yml:10:15:10:50 | github.event.pull_request.title | successor | .github/workflows/arg_injection.yml:43:14:48:111 | # VULNERABLE\nsed -e 's#<branch_to_sync>#TITLE#' \\\n -e 's#<sot_repo>#${{ env.sot_repo }}#' \\\n -e 's#<destination_repo>#${TITLE}#' \\\n .github/workflows/common-copybara.bara.sky.template > .github/workflows/common-copybara.bara.sky\n | |
14 | | -| .github/workflows/arg_injection.yml:10:15:10:50 | github.event.pull_request.title | successor | .github/workflows/arg_injection.yml:49:14:52:41 | # VULNERABLE\nBODY=$(git log --format=%s)\nsed "s/FOO/$BODY/g" > /tmp/foo\n | |
15 | | -| .github/workflows/arg_injection.yml:10:15:10:50 | github.event.pull_request.title | successor | .github/workflows/arg_injection.yml:53:14:56:41 | # VULNERABLE\nBODY=$(git diff --name-only HEAD)\nsed "s/FOO/$BODY/g" > /tmp/foo\n | |
16 | | -| .github/workflows/arg_injection.yml:10:15:10:50 | github.event.pull_request.title | successor | .github/workflows/arg_injection.yml:57:14:60:41 | # VULNERABLE\nBODY=$(git diff --name-only HEAD )\nsed "s/FOO/$BODY/g" > /tmp/foo\n | |
17 | | -| .github/workflows/arg_injection.yml:10:15:10:50 | github.event.pull_request.title | successor | .github/workflows/arg_injection.yml:61:14:64:41 | # VULNERABLE\nBODY=$(git diff --name-only HEAD^ \| xargs)\nsed "s/FOO/$BODY/g" > /tmp/foo\n | |
18 | | -| .github/workflows/arg_injection.yml:10:15:10:50 | github.event.pull_request.title | successor | .github/workflows/arg_injection.yml:65:14:67:67 | # NOT VULNERABLE\necho "value=$(git log -1 --pretty=%s)" >> $GITHUB_OUTPUT\n | |
19 | | -| .github/workflows/arg_injection.yml:10:15:10:50 | github.event.pull_request.title | successor | .github/workflows/arg_injection.yml:68:14:70:33 | # NOT VULNERABLE\ngit log -1 --pretty=%s\n | |
20 | | -| .github/workflows/arg_injection.yml:10:15:10:50 | github.event.pull_request.title | successor | .github/workflows/arg_injection.yml:71:14:74:41 | # NOT VULNERABLE\nBODY=$(git log --format=%s)\nsed -E 's/\\s+/\\n/g' <<<"$BODY"\n | |
0 commit comments