FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

Security: Fix untrusted input vulnerability in release workflow by swlodarski-sumoheavy · Pull Request #419 · bitpay/java-bitpay-client · GitHub

Repository navigation

Security: Fix untrusted input vulnerability in release workflow - #419

Merged
bobbrodie merged 1 commit into
bitpay:10.2.xfrom
swlodarski-sumoheavy:10.2.x-gh-actions-untrusted-input
Feb 2, 2026
Merged

bobbrodie merged 1 commit into
bitpay:10.2.xfrom
swlodarski-sumoheavy:10.2.x-gh-actions-untrusted-input

Conversation

Copy link
Copy Markdown
Collaborator

Security Fix: Prevent Command Injection in Release Workflow

Summary

This PR fixes a command injection vulnerability in the GitHub Actions release workflow by moving all untrusted inputs and GitHub context variables to environment variables.

Problem

The workflow was directly interpolating user inputs and GitHub context variables into shell commands, which could allow command injection attacks. Specifically:

  • ${{ github.event.release.name }} - GitHub context variable
  • ${{ github.event.release.body }} - GitHub context variable

Solution

All potentially untrusted values are now passed through environment variables before being used in shell commands. This ensures they are treated as literal strings rather than being evaluated as code.

Changes made:

  1. Removed the intermediate extraction step that passed untrusted input through GITHUB_OUTPUT
  2. Changed to use environment variables (RELEASE_TITLE, RELEASE_BODY) to safely pass GitHub event data
  3. Updated script to reference environment variables instead of directly interpolating GitHub context expressions

Security Impact

This follows the security best practices outlined in the GitHub Security Lab advisory and prevents potential command injection through GitHub Actions expressions.

Testing

  • Workflow syntax is valid
  • No functional changes to workflow behavior
  • All steps continue to work as expected

bobbrodie merged commit 5675c55 into bitpay:10.2.x Feb 2, 2026
5 checks passed
bobbrodie added this to the v10.3.0 milestone Feb 28, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

2 participants


Back | FazBrowse Home | New Git URL