mirror of
https://github.com/TeamNewPipe/NewPipe
synced 2026-01-27 05:13:35 +00:00
ci: fix shell injection in backport workflow
This commit is contained in:
4
.github/workflows/backport-pr.yml
vendored
4
.github/workflows/backport-pr.yml
vendored
@@ -25,9 +25,11 @@ jobs:
|
||||
- uses: actions/checkout@v4
|
||||
- name: Get backport metadata
|
||||
# the target branch is the first argument after `/backport`
|
||||
env:
|
||||
COMMENT_BODY: ${{ github.event.comment.body }}
|
||||
run: |
|
||||
set -euo pipefail
|
||||
body="${{ github.event.comment.body }}"
|
||||
body="$COMMENT_BODY"
|
||||
|
||||
line=${body%%$'\n'*} # Get the first line
|
||||
if [[ $line =~ ^/backport[[:space:]]+([^[:space:]]+) ]]; then
|
||||
|
||||
Reference in New Issue
Block a user