Skip to content

Merge rc/3.22 into main#21994

Merged
henrymercer merged 3 commits into
mainfrom
henrymercer/mergeback-rc-3-22-into-main
Jun 17, 2026
Merged

Merge rc/3.22 into main#21994
henrymercer merged 3 commits into
mainfrom
henrymercer/mergeback-rc-3-22-into-main

Conversation

@henrymercer

Copy link
Copy Markdown
Contributor

No description provided.

@github-actions github-actions Bot added documentation Actions Analysis of GitHub Actions labels Jun 17, 2026
@henrymercer henrymercer marked this pull request as ready for review June 17, 2026 10:05
@henrymercer henrymercer requested a review from a team as a code owner June 17, 2026 10:05
Copilot AI review requested due to automatic review settings June 17, 2026 10:05

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR merges rc/3.22 into main, bringing in a metadata correction for the actions/untrusted-checkout/medium query so its name/description/alert text consistently describe detection in a non-privileged workflow context.

Changes:

  • Update actions/untrusted-checkout/medium query metadata and alert message to refer to a non-privileged context.
  • Refresh the corresponding test .expected output to match the updated alert message.
  • Add a change note documenting the query metadata correction.
Show a summary per file
File Description
actions/ql/test/query-tests/Security/CWE-829/UntrustedCheckoutMedium.expected Updates expected test output strings to match the revised non-privileged alert wording.
actions/ql/src/Security/CWE-829/UntrustedCheckoutMedium.ql Adjusts the query header metadata and alert message to describe non-privileged workflow context.
actions/ql/src/change-notes/2026-06-04-untrusted-checkout-medium-metadata.md Adds a queryMetadata change note documenting the correction.

Copilot's findings

  • Files reviewed: 3/3 changed files
  • Comments generated: 0

@henrymercer henrymercer merged commit 929870d into main Jun 17, 2026
21 checks passed
@henrymercer henrymercer deleted the henrymercer/mergeback-rc-3-22-into-main branch June 17, 2026 11:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Actions Analysis of GitHub Actions documentation Mergeback

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants