[release/v7.4] Add CodeQL suppressions for PowerShell intended behavior (#25376)

Co-authored-by: Anam Navied <anam.naviyou@gmail.com>
Co-authored-by: Travis Plunk <travis.plunk@microsoft.com>
This commit is contained in:
PowerShell Team Bot
2025-05-02 12:36:21 -07:00
committed by GitHub
co-authored by Anam Navied Travis Plunk
parent a2f1b7f4b2
commit ee53c67b9d
3 changed files with 3 additions and 0 deletions
@@ -684,6 +684,7 @@ namespace Microsoft.PowerShell.Commands
{
// CoreCLR doesn't allow re-load TPA assemblies with different API (i.e. we load them by name and now want to load by path).
// LoadAssemblyHelper helps us avoid re-loading them, if they already loaded.
// codeql[cs/dll-injection-remote] - This is expected PowerShell behavior and integral to the purpose of the class. It allows users to load any C# dependencies they need for their PowerShell application and add other types they require.
Assembly assembly = LoadAssemblyHelper(assemblyName) ?? Assembly.LoadFrom(ResolveAssemblyName(assemblyName, false));
if (PassThru)
@@ -1792,6 +1792,7 @@ namespace Microsoft.PowerShell.Commands
ContentDispositionHeaderValue contentDisposition = new("form-data");
contentDisposition.Name = LanguagePrimitives.ConvertTo<string>(fieldName);
// codeql[cs/information-exposure-through-exception] - PowerShell is an on-premise product, meaning local users would already have access to the binaries and stack traces. Therefore, the information would not be exposed in the same way it would be for an ASP .NET service.
StringContent result = new(LanguagePrimitives.ConvertTo<string>(fieldValue));
result.Headers.ContentDisposition = contentDisposition;
@@ -1385,6 +1385,7 @@ namespace System.Management.Automation
{
try
{
// codeql[cs/dll-injection-remote] - The dll is loaded during the initial state setup, which is expected behavior. This allows users hosting PowerShell to load additional C# types to enable their specific scenarios.
loadedAssembly = Assembly.LoadFrom(filePath);
return loadedAssembly;
}