Open
Description
I'm adding subfeatures to bot-conditions
and template-injection
for proofs-of-concept, but there are several other audits that probably make sense to include subspans for:
-
unsound-contains
(for the offendingcontains(...)
call + context use) -
github-env
for offendingGITHUB_ENV
writes - Others?