Skip to content

Upgrade SonarSource/sonarqube-scan-action #10

@ethan-mfb

Description

@ethan-mfb

Upgrade SonarSource/sonarqube-scan-action to version 5.3.1 or later

Description: 

A command injection vulnerability was discovered in the SonarQube Scan GitHub Action that allows untrusted input arguments to be processed without proper sanitization. Arguments sent to the action are treated as shell expressions, allowing potential execution of arbitrary commands.

References:

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions