release.yml: pass the tag through env instead of interpolating it into shell - #5
Merged
Merged
Conversation
Two run steps expanded ${{ github.event.release.tag_name }} (and the repo
name) directly into the script text, so a crafted tag name would execute as
shell. They now read $TAG / $REPO from env. The build job's checkout also
stops persisting the token (persist-credentials: false); it never pushes.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #3, from review:
release.ymlexpanded event data straight into shell scripts.Why
release.yml:25andrelease.yml:53put${{ github.event.release.tag_name }}, and on line 53${{ github.repository }}, directly intorun:scripts. GitHub substitutes the expression into the script text before the shell runs, so a tag named, for example,v1$(curl …)would execute as code in a job that hascontents: write.What changed
env:(TAG,REPO) and use"$TAG"/"$REPO". No${{ }}expression is left in anyrun:line in either workflow.actions/checkoutsetspersist-credentials: false. That job only builds and uploadsdist/, so it never needs the token in.git/config.Verification
actionlint1.7.7: clean on both workflows.zizmor1.30.1 onrelease.yml:main: 2 ×template-injection(lines 25 and 53), 1 ×artipacked, 8 ×unpinned-uses;unpinned-usesremain (see below).TAG='v0.2.0$(echo INJECTED)' python scripts/check_release.py "$TAG"printserror: tag v0.2.0$(echo INJECTED) does not match __version__ 0.2.0and exits 1: the tag is treated as data;TAG=v0.2.0printsok: 0.2.0 is ready to release.Not done here
unpinned-usesfindings: actions are referenced by tag (@v4,@release/v1), as in the rest of the repo. Pinning them to commit SHAs, plus Dependabot to keep the pins current, is worth doing for this workflow because its publish jobs holdid-token: write. It is a separate, repo-wide change.🤖 Generated with Claude Code