RELEASE @W-19079373@ Prevent PR title injection in validate-pr workflow - #367
Conversation
Hardens the validate-pr GitHub Actions workflow against PR-title script
injection (CWE-94) by passing the untrusted PR title and base ref through
environment variables instead of inline ${{ }} interpolation, and adds a
least-privilege 'permissions: contents: read' block.
CI-only change (.github/workflows/validate-pr.yml); no runtime/package
changes. Port of the fix already merged to dev (#366) onto main.
Fixes W-19079373.
|
Git2Gus App is installed but the |
…-test failure on VS Code 1.131.0 (cherry picked from commit 622f857)
There was a problem hiding this comment.
@nikhil-mittal-165 Same comment as the previous PR. Can we take care of head_ref as well?
Extends the PR-title injection hardening to the branch-ref checks: passes
github.head_ref through an env var (HEAD_REF) and replaces the two inline
${{ startsWith(...) }} expressions with shell glob matches (== m2d/* and
== release-*). This removes the last ${{ }} interpolations from the run
block so all untrusted inputs are handled uniformly as data.
Behavior is unchanged; verified the glob matches are equivalent to the
prior startsWith() checks. Addresses review feedback on #2079 (mirror).
aruntyagiTutu
left a comment
There was a problem hiding this comment.
Port of the already-reviewed/approved PR-title-injection fix (dev #366) onto main, plus it carries forward the previously-approved @vscode/test-electron 2.5.2→3.1.0 bump (dev #365, fixing the e2e smoke-test break on VS Code 1.131.0) since main hadn't picked that up yet. Both changes are unmodified ports of already-approved dev commits — validate-pr.yml diff is identical to #366 (including the follow-up head_ref env fix), and the test-electron/package-lock diff matches what I approved on #365.
CI-only + dev-dependency change, no product runtime impact. CI green across macOS/Ubuntu/Windows. Approving.
Hardens the validate-pr GitHub Actions workflow against PR-title script injection (CWE-94) by passing the untrusted PR title and base ref through environment variables instead of inline ${{ }} interpolation, and adds a least-privilege 'permissions: contents: read' block.
CI-only change (.github/workflows/validate-pr.yml); no runtime/package changes. Port of the fix already merged to dev (#366) onto main.
Fixes W-19079373.