product1 distinct publisher
CodeQL 2.26.3 treats workflow files as code, and cache poisoning as a finding you must triage
GitHub's August release retunes Actions queries for cache poisoning, output clobbering and untrusted checkouts. Most of the work went into cutting false positives, not adding coverage.
Publishers:devops.com
Reality
- Evidence58
- Adoption28
- Hype gap+6
- Incentives44
- Confidence60