1
0
mirror of https://github.com/TeamNewPipe/NewPipe synced 2026-01-27 05:13:35 +00:00

ci: fix shell injection in backport workflow

This commit is contained in:
RinCodeForge927
2026-01-13 20:42:10 +07:00
parent 77d62deeed
commit 7dc38286c0

View File

@@ -25,9 +25,11 @@ jobs:
- uses: actions/checkout@v4
- name: Get backport metadata
# the target branch is the first argument after `/backport`
env:
COMMENT_BODY: ${{ github.event.comment.body }}
run: |
set -euo pipefail
body="${{ github.event.comment.body }}"
body="$COMMENT_BODY"
line=${body%%$'\n'*} # Get the first line
if [[ $line =~ ^/backport[[:space:]]+([^[:space:]]+) ]]; then