Skip to content

Commit baf7704

Browse files
committed
chore: prevent script injection
1 parent a60cc06 commit baf7704

3 files changed

Lines changed: 6 additions & 4 deletions

File tree

.github/workflows/merge-release.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -36,8 +36,9 @@ jobs:
3636

3737
- name: Resolve release branch
3838
id: branch
39+
env:
40+
INPUT: ${{ inputs.branch }}
3941
run: |
40-
INPUT="${{ inputs.branch }}"
4142
if [ -n "$INPUT" ]; then
4243
BRANCH="$INPUT"
4344
else

.github/workflows/prepare-release.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -43,9 +43,9 @@ jobs:
4343

4444
- name: Validate version
4545
id: version
46+
env:
47+
INPUT: ${{ inputs.version }}
4648
run: |
47-
INPUT="${{ inputs.version }}"
48-
4949
# Must be an explicit x.y.z semver
5050
if ! echo "$INPUT" | grep -qE '^\d+\.\d+\.\d+$'; then
5151
echo "❌ Invalid version: '$INPUT'. Must be an explicit semver like '1.3.0'."

.github/workflows/publish-release.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -35,8 +35,9 @@ jobs:
3535

3636
- name: Resolve release branch
3737
id: branch
38+
env:
39+
INPUT: ${{ inputs.branch }}
3840
run: |
39-
INPUT="${{ inputs.branch }}"
4041
if [ -n "$INPUT" ]; then
4142
BRANCH="$INPUT"
4243
else

0 commit comments

Comments
 (0)