Skip to content

Do not add binary to PATH#64

Merged
tangrufus merged 1 commit intomainfrom
sec
May 10, 2026
Merged

Do not add binary to PATH#64
tangrufus merged 1 commit intomainfrom
sec

Conversation

@tangrufus
Copy link
Copy Markdown
Member

@tangrufus tangrufus commented May 10, 2026

Fix PATH environment variable built from user-controlled sources.

Fix https://github.com/typisttech/php-matrix-action/security/code-scanning/2

Comment thread action.yml Fixed
@tangrufus tangrufus force-pushed the sec branch 2 times, most recently from d55d204 to 3a0a6c7 Compare May 10, 2026 20:07
@tangrufus tangrufus changed the title Store binary under runner.temp instead of github.action_path Do not add binary to PATH May 10, 2026
Fix `PATH` environment variable built from
user-controlled sources.

Fix https://github.com/typisttech/php-matrix-action/security/code-scanning/2
@tangrufus tangrufus merged commit 4c1898e into main May 10, 2026
124 checks passed
@tangrufus tangrufus deleted the sec branch May 10, 2026 20:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Development

Successfully merging this pull request may close these issues.

2 participants