Skip to content

SEC: fix exploitable template-injection surface (3/n)#373

Closed
neutrinoceros wants to merge 1 commit intoOpenAstronomy:mainfrom
neutrinoceros:sec/no-template-injection-3
Closed

SEC: fix exploitable template-injection surface (3/n)#373
neutrinoceros wants to merge 1 commit intoOpenAstronomy:mainfrom
neutrinoceros:sec/no-template-injection-3

Conversation

@neutrinoceros
Copy link
Contributor

ref #364

@neutrinoceros
Copy link
Contributor Author

upon carfeul look I think this one cannot work: shell expansion is needed for this to work correctly, so zizmor's default strategy to guard against it is doomed to fail.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant