Skip to content

Commit 8f3112e

Browse files
committed
fix(release): reject dispatch script injection
1 parent bf3595b commit 8f3112e

3 files changed

Lines changed: 13 additions & 2 deletions

File tree

‎.github/workflows/publish-core.yml‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,9 @@ jobs:
4141
cache: false
4242
install: false
4343
- name: Create release plan
44-
run: node tools/release/plan.ts --group core --bump "${{ inputs.bump }}" --output release-plan.json
44+
env:
45+
RELEASE_BUMP: ${{ inputs.bump }}
46+
run: node tools/release/plan.ts --group core --bump "$RELEASE_BUMP" --output release-plan.json
4547
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
4648
with:
4749
name: core-release-plan

‎.github/workflows/publish-yoga.yml‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,9 @@ jobs:
4141
cache: false
4242
install: false
4343
- name: Create release plan
44-
run: node tools/release/plan.ts --group yoga --bump "${{ inputs.bump }}" --output release-plan.json
44+
env:
45+
RELEASE_BUMP: ${{ inputs.bump }}
46+
run: node tools/release/plan.ts --group yoga --bump "$RELEASE_BUMP" --output release-plan.json
4547
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
4648
with:
4749
name: yoga-release-plan

‎tools/release/check-config.ts‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -63,6 +63,13 @@ for (const group of Object.values(releaseGroups)) {
6363
assert(workflow.includes("id-token: write"));
6464
assert.equal(workflow.match(/id-token: write/g)?.length, 1);
6565
assert(workflow.includes(`tools/release/plan.ts --group ${group.name}`));
66+
assert.equal(
67+
/^\s*run:.*\$\{\{\s*inputs\./m.test(workflow),
68+
false,
69+
`${group.workflow} must pass dispatch inputs through step environment variables`,
70+
);
71+
assert(workflow.includes("RELEASE_BUMP: ${{ inputs.bump }}"));
72+
assert(workflow.includes('--bump "$RELEASE_BUMP"'));
6673
assert.equal(workflow.includes("NODE_AUTH_TOKEN"), false);
6774
assert.equal(workflow.includes("cache: true"), false);
6875
for (const match of workflow.matchAll(/^\s*- uses: (?<action>[^\s#]+).*$/gm)) {

0 commit comments

Comments
 (0)