1
0
Fork 0
toolkit/.github
Patrick Ellis 8f032d304a
Upgrade codeql actions to v2
Currently we're using v1, and there have been some important changes since then.

In particular, the latest version, v2.14.6, contains an important security patch:

> The CodeQL CLI no longer supports the `SEMMLE_JAVA_ARGS` environment variable. All previous versions of the CodeQL CLI perform command substitution on the `SEMMLE_JAVA_ARGS` value (for example, replacing `'$(echo foo)'` with `'foo'`) when starting a new Java virtual machine, which, depending on the execution environment, may have security implications. Users are advised to check their environments for possible `SEMMLE_JAVA_ARGS` misuse.

See the [codeql-cli-binaries release notes](https://github.com/github/codeql-cli-binaries/releases/tag/v2.14.4) for full details.
2023-09-27 15:18:59 -04:00
..
ISSUE_TEMPLATE Update Bug Report Template (#466) 2020-05-19 13:43:20 -04:00
workflows Upgrade codeql actions to v2 2023-09-27 15:18:59 -04:00
CONTRIBUTING.md Audit Fix (#1480) 2023-08-03 16:36:11 -04:00