From 2da9ddbff60c35ce2f8bfdc5bcb884c8fa29295c Mon Sep 17 00:00:00 2001 From: Xinyu Zhang Date: Fri, 27 Mar 2026 19:01:45 -0400 Subject: [PATCH] Removed false positive injection sink models for the skip-collectors input of veracode/veracode-sca. --- actions/ql/lib/ext/manual/veracode_veracode-sca.model.yml | 1 - .../ql/src/change-notes/2026-03-27-veracode#veracode-sca.md | 4 ++++ 2 files changed, 4 insertions(+), 1 deletion(-) create mode 100644 actions/ql/src/change-notes/2026-03-27-veracode#veracode-sca.md diff --git a/actions/ql/lib/ext/manual/veracode_veracode-sca.model.yml b/actions/ql/lib/ext/manual/veracode_veracode-sca.model.yml index d3e1daae67ac..93dc73f5fdde 100644 --- a/actions/ql/lib/ext/manual/veracode_veracode-sca.model.yml +++ b/actions/ql/lib/ext/manual/veracode_veracode-sca.model.yml @@ -5,5 +5,4 @@ extensions: data: - ["veracode/veracode-sca", "*", "input.url", "command-injection", "manual"] - ["veracode/veracode-sca", "*", "input.path", "command-injection", "manual"] - - ["veracode/veracode-sca", "*", "input.skip-collectors", "command-injection", "manual"] - ["veracode/veracode-sca", "*", "input.url", "command-injection", "manual"] diff --git a/actions/ql/src/change-notes/2026-03-27-veracode#veracode-sca.md b/actions/ql/src/change-notes/2026-03-27-veracode#veracode-sca.md new file mode 100644 index 000000000000..a27a2a134f67 --- /dev/null +++ b/actions/ql/src/change-notes/2026-03-27-veracode#veracode-sca.md @@ -0,0 +1,4 @@ +--- +category: minorAnalysis +--- +* Removed false positive injection sink models for the `skip-collectors` input of `veracode/veracode-sca`. \ No newline at end of file