Skip to content

Actions: Improve actions cache poisoning code injection wording - #22266

Open
JarLob wants to merge 2 commits into
github:mainfrom
JarLob:improve/actions-cache-poisoning-code-injection-wording
Open

Actions: Improve actions cache poisoning code injection wording#22266
JarLob wants to merge 2 commits into
github:mainfrom
JarLob:improve/actions-cache-poisoning-code-injection-wording

Conversation

@JarLob

@JarLob JarLob commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

No description provided.

Copilot AI review requested due to automatic review settings July 31, 2026 20:59
@JarLob
JarLob requested a review from a team as a code owner July 31, 2026 20:59
@github-actions github-actions Bot added documentation Actions Analysis of GitHub Actions labels Jul 31, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Rewords the Actions cache-poisoning query name and alert message for clarity.

Changes:

  • Simplifies the query name.
  • Clarifies default-branch cache poisoning risk.
  • Updates expected test output and change notes.
Show a summary per file
File Description
actions/ql/test/query-tests/Security/CWE-349/CachePoisoningViaCodeInjection.expected Updates expected alert wording.
actions/ql/src/Security/CWE-349/CachePoisoningViaCodeInjection.ql Rewords query metadata and alert text.
actions/ql/src/change-notes/2026-07-31-cache-poisoning-code-injection-wording.md Documents the wording change.

Review details

  • Files reviewed: 3/3 changed files
  • Comments generated: 0
  • Review effort level: Balanced

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Actions Analysis of GitHub Actions documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants