Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
security(gha): fix potential for shell injection (#4099)
Running these workflows is gated pretty well, but this mitigates the potential for a script injection attack by passing the input to an intermediary environment variable first. See https://docs.github.com/en/actions/security-for-github-actions/security-guides/security-hardening-for-github-actions#example-of-a-script-injection-attack for more details.
- Loading branch information