| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
There was a problem hiding this comment.
This pull request hardens the GitHub Actions email-notification workflow by HTML-escaping dynamic, workflow-sourced values before embedding them into HTML email templates, reducing the risk of HTML/attribute injection.
Changes:
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Sorry, something went wrong.
|
🎉 This PR is included in version 2.1.0 🎉 The release is available on GitHub release Your semantic-release bot 📦🚀 |
Sorry, something went wrong.
NPM (ContentProcessorWeb pnpm overrides): - websocket-driver -> ^0.7.5 (CRITICAL, microsoft#541) - axios 1.16.0 -> 1.18.0 (microsoft#558) - brace-expansion ^2.0.3 -> ^2.1.2 (microsoft#587) - fast-uri 3.1.2 -> 3.1.4 (microsoft#602/microsoft#604) - immutable ^5.1.5 -> ^5.1.8 (microsoft#600/microsoft#601) - js-yaml ^4.2.0 -> ^4.3.0 (microsoft#588) - shell-quote ^1.8.4 -> ^1.9.0 (microsoft#589) - svgo ^2.8.1 -> ^2.8.3 (microsoft#603) - react-router-dom 7.15.1 -> 7.18.1 (microsoft#611 DoS) Python (uv): - pillow 12.2.0 -> 12.3.0 (ContentProcessor) - pyasn1 0.6.3 -> 0.6.4 (ContentProcessor, Workflow) - mcp 1.25.0 -> 1.28.1 (Workflow); transitive mcp -> 1.29.0 (ContentProcessor) Deferred: react-router microsoft#610 (RSC CSRF, fixed only in v8.3.0 major; RSC mode unused by this CRA SPA). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 22668762-66d8-4311-b4c2-ee147376b71d
| Back | FazBrowse Home | New Git URL |
Purpose
This pull request enhances the security of the email notification workflow by ensuring that dynamic values embedded in email templates are properly HTML-escaped. This prevents potential HTML or attribute injection vulnerabilities from workflow inputs such as actor names, branch names, and resource group names. Additionally, the workflow now consistently uses these escaped variables throughout the email templates for all notification scenarios.
The most important changes are:
Security Improvements:
Email Template Consistency:
These changes collectively improve the robustness and security of the workflow's email notifications.
Does this introduce a breaking change?
Golden Path Validation
Deployment Validation
What to Check
Verify that the following are valid
Other Information