mirror of
https://github.com/XRPLF/clio.git
synced 2025-11-20 03:35:55 +00:00
fix: Do not allow command injection in GitHub workflows (#2270)
This commit is contained in:
10
.github/workflows/release_impl.yml
vendored
10
.github/workflows/release_impl.yml
vendored
@@ -69,9 +69,9 @@ jobs:
|
|||||||
shell: bash
|
shell: bash
|
||||||
if: ${{ inputs.generate_changelog }}
|
if: ${{ inputs.generate_changelog }}
|
||||||
run: |
|
run: |
|
||||||
LAST_TAG=$(gh release view --json tagName -q .tagName)
|
LAST_TAG="$(gh release view --json tagName -q .tagName)"
|
||||||
LAST_TAG_COMMIT=$(git rev-parse $LAST_TAG)
|
LAST_TAG_COMMIT="$(git rev-parse $LAST_TAG)"
|
||||||
BASE_COMMIT=$(git merge-base HEAD $LAST_TAG_COMMIT)
|
BASE_COMMIT="$(git merge-base HEAD $LAST_TAG_COMMIT)"
|
||||||
git-cliff "${BASE_COMMIT}..HEAD" --ignore-tags "nightly|-b"
|
git-cliff "${BASE_COMMIT}..HEAD" --ignore-tags "nightly|-b"
|
||||||
cat CHANGELOG.md >> "${RUNNER_TEMP}/release_notes.md"
|
cat CHANGELOG.md >> "${RUNNER_TEMP}/release_notes.md"
|
||||||
|
|
||||||
@@ -108,10 +108,10 @@ jobs:
|
|||||||
if: ${{ github.event_name != 'pull_request' }}
|
if: ${{ github.event_name != 'pull_request' }}
|
||||||
shell: bash
|
shell: bash
|
||||||
run: |
|
run: |
|
||||||
gh release create ${{ inputs.version }} \
|
gh release create "${{ inputs.version }}" \
|
||||||
${{ inputs.overwrite_release && '--prerelease' || '' }} \
|
${{ inputs.overwrite_release && '--prerelease' || '' }} \
|
||||||
--title "${{ inputs.title }}" \
|
--title "${{ inputs.title }}" \
|
||||||
--target $GITHUB_SHA \
|
--target "${GITHUB_SHA}" \
|
||||||
${{ inputs.draft && '--draft' || '' }} \
|
${{ inputs.draft && '--draft' || '' }} \
|
||||||
--notes-file "${RUNNER_TEMP}/release_notes.md" \
|
--notes-file "${RUNNER_TEMP}/release_notes.md" \
|
||||||
./release_artifacts/clio_server*
|
./release_artifacts/clio_server*
|
||||||
|
|||||||
Reference in New Issue
Block a user