Skip to content

fix(security): GHA shell injection on deploy acknowledge - #12

Merged
scrimshawlife-ctrl merged 1 commit into
mainfrom
cursor/fix-gha-shell-injection-d22a
Sep 17, 2026
Merged

scrimshawlife-ctrl merged 1 commit into
mainfrom
cursor/fix-gha-shell-injection-d22a

Conversation

@scrimshawlife-ctrl

Copy link
Copy Markdown
Contributor

Move inputs.acknowledge into env: ACKNOWLEDGE so the workflow_dispatch input is not interpolated into the shell script (avoids GHA shell injection).

@scrimshawlife-ctrl
scrimshawlife-ctrl requested a review from a team as a code owner September 17, 2026 22:02
@github-actions

Copy link
Copy Markdown

CC @Zero-State-LLC/partner-agents. Flagged for shared triage.

@prabu-openclaw prabu-openclaw left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Correct fix for GHA shell injection: moves inputs.acknowledge from direct ${{ }} interpolation into the run: script to an env var (ACKNOWLEDGE), so untrusted/malicious input can't be shell-injected into the step. Logic unchanged, checks pass (build + validate matrix), single-line diff, no other risk surface.

@scrimshawlife-ctrl
scrimshawlife-ctrl merged commit d2fc4b7 into main Sep 17, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants