diff --git a/.github/workflows/api-release.yml b/.github/workflows/api-release.yml index 6df326e89..6bbd22597 100644 --- a/.github/workflows/api-release.yml +++ b/.github/workflows/api-release.yml @@ -41,8 +41,13 @@ jobs: run: npm install -g npm@latest && npm --version - name: Set version from tag + # Same shell-injection shape as #227: keep the input in the + # environment even though this workflow only receives the + # already-validated tag from release.yml. + env: + INPUT_TAG: ${{ inputs.tag }} run: | - TAG_NAME="${{ inputs.tag }}" + TAG_NAME="$INPUT_TAG" if [ -z "$TAG_NAME" ]; then echo "Error: No tag specified." diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 4d9b1cd5c..9d54e95a2 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -39,10 +39,16 @@ jobs: - name: Resolve tag id: meta shell: bash + # The tag rides in through the environment, never through ${{ }} + # interpolation: the runner expands expressions before bash parses + # the script, so interpolated input runs as code before the format + # check below ever sees it (#227). + env: + INPUT_TAG: ${{ inputs.tag }} run: | set -euo pipefail if [[ "${{ github.event_name }}" == "workflow_dispatch" ]]; then - TAG="${{ inputs.tag || '' }}" + TAG="${INPUT_TAG:-}" if [[ -z "$TAG" ]]; then echo "When dispatching manually, you must provide 'tag' (e.g. v1.2.3)." >&2 exit 1