diff --git a/.github/workflows/preview-smoke.yml b/.github/workflows/preview-smoke.yml index 976882b..8226e9d 100644 --- a/.github/workflows/preview-smoke.yml +++ b/.github/workflows/preview-smoke.yml @@ -40,11 +40,20 @@ jobs: steps: - name: Decide id: check + env: + # Route PR body + fork flag through env vars instead of inline + # ${{ }} interpolation. Direct ${{ github.event.pull_request.body }} + # in a shell command pastes arbitrary user-controlled text (parens, + # backticks, pipes, heredocs) directly into the script — both a + # syntax-error risk AND a shell-injection vector. Quoting the env + # vars below makes both safe. + PR_BODY: ${{ github.event.pull_request.body }} + PR_IS_FORK: ${{ github.event.pull_request.head.repo.fork }} run: | - if [[ "${{ github.event.pull_request.head.repo.fork }}" == "true" ]]; then + if [[ "$PR_IS_FORK" == "true" ]]; then echo "should_run=false" >> $GITHUB_OUTPUT echo "::notice::Smoke skipped on fork PR (bypass secret unavailable to forks)" - elif echo "${{ github.event.pull_request.body }}" | grep -qE 'pipeline:.*skip.*\bsmoke\b'; then + elif echo "$PR_BODY" | grep -qE 'pipeline:.*skip.*\bsmoke\b'; then echo "should_run=false" >> $GITHUB_OUTPUT echo "::notice::Smoke skipped via pipeline directive" else diff --git a/.github/workflows/visual-diff.yml b/.github/workflows/visual-diff.yml index 8a12afa..75e3578 100644 --- a/.github/workflows/visual-diff.yml +++ b/.github/workflows/visual-diff.yml @@ -36,11 +36,16 @@ jobs: should_run: ${{ steps.check.outputs.should_run }} steps: - id: check + env: + # See preview-smoke.yml for the rationale: ${{ github.event.* }} + # inlined into shell is a syntax-error + injection vector. + PR_BODY: ${{ github.event.pull_request.body }} + PR_IS_FORK: ${{ github.event.pull_request.head.repo.fork }} run: | - if [[ "${{ github.event.pull_request.head.repo.fork }}" == "true" ]]; then + if [[ "$PR_IS_FORK" == "true" ]]; then echo "should_run=false" >> $GITHUB_OUTPUT echo "::notice::Visual diff skipped on fork PR (bypass secret unavailable to forks)" - elif echo "${{ github.event.pull_request.body }}" | grep -qE 'pipeline:.*skip.*\bvisual\b'; then + elif echo "$PR_BODY" | grep -qE 'pipeline:.*skip.*\bvisual\b'; then echo "should_run=false" >> $GITHUB_OUTPUT echo "::notice::Visual diff skipped via pipeline directive" else