Skip to content

Commit 8598e93

Browse files
[FSSDK-10665] fix: Github Actions YAML files vulnerable to script injections corrected (#77)
1 parent 48d4dd5 commit 8598e93

File tree

1 file changed

+14
-6
lines changed

1 file changed

+14
-6
lines changed

.github/workflows/flutter.yml

+14-6
Original file line numberDiff line numberDiff line change
@@ -37,14 +37,18 @@ jobs:
3737
path: 'home/runner/travisci-tools'
3838
ref: 'master'
3939
- name: set SDK Branch if PR
40+
env:
41+
HEAD_REF: ${{ github.head_ref }}
4042
if: ${{ github.event_name == 'pull_request' }}
4143
run: |
42-
echo "SDK_BRANCH=${{ github.head_ref }}" >> $GITHUB_ENV
44+
echo "SDK_BRANCH=$HEAD_REF" >> $GITHUB_ENV
4345
- name: set SDK Branch if not pull request
46+
env:
47+
REF_NAME: ${{ github.ref_name }}
4448
if: ${{ github.event_name != 'pull_request' }}
4549
run: |
46-
echo "SDK_BRANCH=${{ github.ref_name }}" >> $GITHUB_ENV
47-
echo "TRAVIS_BRANCH=${{ github.ref_name }}" >> $GITHUB_ENV
50+
echo "SDK_BRANCH=$REF_NAME" >> $GITHUB_ENV
51+
echo "TRAVIS_BRANCH=$REF_NAME" >> $GITHUB_ENV
4852
- name: Trigger build
4953
env:
5054
SDK: android
@@ -75,14 +79,18 @@ jobs:
7579
path: 'home/runner/travisci-tools'
7680
ref: 'master'
7781
- name: set SDK Branch if PR
82+
env:
83+
HEAD_REF: ${{ github.head_ref }}
7884
if: ${{ github.event_name == 'pull_request' }}
7985
run: |
80-
echo "SDK_BRANCH=${{ github.head_ref }}" >> $GITHUB_ENV
86+
echo "SDK_BRANCH=$HEAD_REF" >> $GITHUB_ENV
8187
- name: set SDK Branch if not pull request
88+
env:
89+
REF_NAME: ${{ github.ref_name }}
8290
if: ${{ github.event_name != 'pull_request' }}
8391
run: |
84-
echo "SDK_BRANCH=${{ github.ref_name }}" >> $GITHUB_ENV
85-
echo "TRAVIS_BRANCH=${{ github.ref_name }}" >> $GITHUB_ENV
92+
echo "SDK_BRANCH=$REF_NAME" >> $GITHUB_ENV
93+
echo "TRAVIS_BRANCH=$REF_NAME" >> $GITHUB_ENV
8694
- name: Trigger build
8795
env:
8896
SDK: ios

0 commit comments

Comments
 (0)