diff --git a/actions/ql/src/Security/CWE-829/UnversionedImmutableAction.ql b/actions/ql/src/Security/CWE-829/UnversionedImmutableAction.ql index ac8cc249318e..8cc79b1091a5 100644 --- a/actions/ql/src/Security/CWE-829/UnversionedImmutableAction.ql +++ b/actions/ql/src/Security/CWE-829/UnversionedImmutableAction.ql @@ -7,6 +7,7 @@ * @id actions/unversioned-immutable-action * @tags security * actions + * internal * external/cwe/cwe-829 */ diff --git a/actions/ql/src/codeql-suites/actions-all.qls b/actions/ql/src/codeql-suites/actions-all.qls index be9be8666201..81b57e66e1b8 100644 --- a/actions/ql/src/codeql-suites/actions-all.qls +++ b/actions/ql/src/codeql-suites/actions-all.qls @@ -1,4 +1,4 @@ -- description: Standard Code Scanning queries for Actions +- description: Standard Code Scanning queries for GitHub Actions - queries: . - include: kind: diff --git a/actions/ql/src/codeql-suites/actions-bughalla.qls b/actions/ql/src/codeql-suites/actions-bughalla.qls index 0d718fac616e..98e4dc845f90 100644 --- a/actions/ql/src/codeql-suites/actions-bughalla.qls +++ b/actions/ql/src/codeql-suites/actions-bughalla.qls @@ -1,4 +1,4 @@ -- description: Bughalla queries for Actions +- description: Bughalla queries for GitHub Actions - queries: '.' - exclude: tags contain: diff --git a/actions/ql/src/codeql-suites/actions-code-scanning.qls b/actions/ql/src/codeql-suites/actions-code-scanning.qls index ce3ff4893356..4cfe07484d96 100644 --- a/actions/ql/src/codeql-suites/actions-code-scanning.qls +++ b/actions/ql/src/codeql-suites/actions-code-scanning.qls @@ -1,4 +1,4 @@ -- description: Standard Code Scanning queries for Actions +- description: Standard Code Scanning queries for GitHub Actions - queries: '.' - include: problem.severity: @@ -8,4 +8,4 @@ tags contain: - experimental - debug - + - internal diff --git a/actions/ql/src/codeql-suites/actions-security-and-quality.qls b/actions/ql/src/codeql-suites/actions-security-and-quality.qls index ef332acb872c..046d8d367646 100644 --- a/actions/ql/src/codeql-suites/actions-security-and-quality.qls +++ b/actions/ql/src/codeql-suites/actions-security-and-quality.qls @@ -1,11 +1,2 @@ -- description: Security-and-quality queries for Actions -- queries: '.' -- include: - problem.severity: - - error - - recommendation -- exclude: - tags contain: - - experimental - - debug - +- description: Security-and-quality queries for GitHub Actions +- import: codeql-suites/actions-security-extended.qls diff --git a/actions/ql/src/codeql-suites/actions-security-extended.qls b/actions/ql/src/codeql-suites/actions-security-extended.qls new file mode 100644 index 000000000000..07276d22dfc8 --- /dev/null +++ b/actions/ql/src/codeql-suites/actions-security-extended.qls @@ -0,0 +1,2 @@ +- description: Security-extended queries for GitHub Actions +- import: codeql-suites/actions-code-scanning.qls