Skip to content

fix(ci): use env vars instead of template expressions in run blocks#138

Merged
jdalton merged 1 commit intomainfrom
fix/zizmor-template-injection
Apr 4, 2026
Merged

fix(ci): use env vars instead of template expressions in run blocks#138
jdalton merged 1 commit intomainfrom
fix/zizmor-template-injection

Conversation

@jdalton
Copy link
Copy Markdown
Collaborator

@jdalton jdalton commented Apr 4, 2026

Replace ${{ steps.X.outputs.Y }} in run blocks with env vars to avoid template injection (zizmor audit).

@jdalton jdalton merged commit 0c96243 into main Apr 4, 2026
12 checks passed
@jdalton jdalton deleted the fix/zizmor-template-injection branch April 4, 2026 13:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant