Symptom
The Maven notification workflow interpolates github.ref_name directly into the gh api URL used to find previous runs.
Steps to reproduce
- Start
.github/workflows/mvn.yml for a branch or tag containing shell metacharacters, such as test$(touch /tmp/marker).
- Inspect the
previous step's gh api command.
Actual result
The expression is expanded before Bash parses the command. Command substitution in the resulting double-quoted URL can run arbitrary commands in the workflow.
Expected result
Use an environment variable or a request parameter for the ref and validate it before constructing the API query.
Evidence
.github/workflows/mvn.yml:86 contains branch=${{ github.ref_name }} inside a shell command.
Symptom
The Maven notification workflow interpolates
github.ref_namedirectly into thegh apiURL used to find previous runs.Steps to reproduce
.github/workflows/mvn.ymlfor a branch or tag containing shell metacharacters, such astest$(touch /tmp/marker).previousstep'sgh apicommand.Actual result
The expression is expanded before Bash parses the command. Command substitution in the resulting double-quoted URL can run arbitrary commands in the workflow.
Expected result
Use an environment variable or a request parameter for the ref and validate it before constructing the API query.
Evidence
.github/workflows/mvn.yml:86containsbranch=${{ github.ref_name }}inside a shell command.