Skip to content

Commit 7851a8a

Browse files
committed
CI: Avoid potential template injection issue in create-upload-suggestions
Solves zizmor's template-injection audit: https://docs.zizmor.sh/audits/#template-injection
1 parent cd7953a commit 7851a8a

File tree

1 file changed

+3
-1
lines changed
  • .github/actions/create-upload-suggestions

1 file changed

+3
-1
lines changed

.github/actions/create-upload-suggestions/action.yml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -145,7 +145,9 @@ runs:
145145
- name: List all changed files tracked and untracked files
146146
shell: bash
147147
run: |
148-
echo "Changed files: ${{ steps.git-changed-files.outputs.CHANGED_FILES }}"
148+
echo "Changed files: ${CHANGED_FILES}"
149+
env:
150+
CHANGED_FILES: ${{ steps.git-changed-files.outputs.CHANGED_FILES }}
149151
- name: Add job summary without changed files
150152
shell: bash
151153
if: ${{ steps.files_changed.outputs.files_changed == 'false' }}

0 commit comments

Comments
 (0)