Repository navigation
Commit 89abcdf
committed
ADFA-4184: Fix run-shell-injection risk in debug.yml Extract Jira step
The "Extract Jira Ticket and Fetch Title" step interpolated github context
(github.repository, github.sha, github.ref) and secrets directly into its
run: script. Those values are attacker-controllable, so a crafted branch or
commit could inject shell code on the runner.
Move every ${{ ... }} interpolation into the step's env: block and reference
them as double-quoted shell variables, per the Semgrep run-shell-injection
guidance. Semgrep p/github-actions now reports 0 findings (was 1).1 parent 5f14ef7 commit 89abcdf
1 file changed
Lines changed: 8 additions & 3 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
251 | 251 | | |
252 | 252 | | |
253 | 253 | | |
| 254 | + | |
| 255 | + | |
| 256 | + | |
| 257 | + | |
| 258 | + | |
254 | 259 | | |
255 | 260 | | |
256 | 261 | | |
| |||
268 | 273 | | |
269 | 274 | | |
270 | 275 | | |
271 | | - | |
| 276 | + | |
272 | 277 | | |
273 | | - | |
| 278 | + | |
274 | 279 | | |
275 | 280 | | |
276 | 281 | | |
| |||
285 | 290 | | |
286 | 291 | | |
287 | 292 | | |
288 | | - | |
| 293 | + | |
289 | 294 | | |
290 | 295 | | |
291 | 296 | | |
| |||
0 commit comments