Adding comprehensive docs for customizing actions/unpinned-tag
query
#19427
+41
−0
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This pull request introduces documentation updates for customizing the behavior of the
UnpinnedActionsTag
query in CodeQL. The changes include detailed instructions on how to extend the list of trusted Action publishers and a reference link to the customization guide. Inspired by lack of visibility here: #18316 (comment)Documentation Enhancements:
Added a customization guide for trusted Action publishers:
A new section in
UnpinnedActionsTag-CUSTOMIZING.md
explains how to configure a data extension model pack to allow specific Action publishers, preventing security alerts for unpinned tags from these publishers. This includes step-by-step instructions and example configuration files.Linked customization guide in primary documentation:
Updated
UnpinnedActionsTag.md
to include a reference to the new customization guide, helping users find the configuration instructions easily.