Repository navigation
security(ci): pass step outcomes to the CodeQL summary through env, not template expansion - #364
Merged
Merged
Conversation
Contributor
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The workflow safely handles step values without unresolved blocking issues.
Review effort: Lite
Findings: None
What changed in this PR
Updates the CodeQL workflow to prevent template-injection risks while preserving scan behavior.
Changes:
- Passes step values through environment variables.
- Reads them from PowerShell environment variables.
- Preserves existing status logic.
| File | Description |
|---|---|
.github/workflows/codeql.yaml |
Secures CodeQL summary value handling. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Chris-Wolfgang
added this pull request to stack #369
September 26, 2026 16:57
…ot template expansion
zizmor reports template-injection against codeql.yaml's "Complete Security Scan"
step: four ${{ steps.* }} expressions are spliced straight into the pwsh script
body, so whatever they expand to becomes code rather than data. Three of them are
GitHub-controlled outcome enums, but steps.check-csharp.outputs.has-csharp is a
step output - exactly the kind of value that can carry PR-influenced content.
repo-template already fixed this; this repository's codeql.yaml predates it. The
four values now arrive as environment variables and the script reads $env:NAME,
so nothing attacker-influenced is ever parsed as PowerShell. Behaviour is
unchanged: the same four variables hold the same four values.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Chris-Wolfgang
force-pushed
the
security/codeql-template-injection
branch
from
September 26, 2026 17:45
7fbd8c9 to
e339483
Compare
This was referenced Sep 26, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes the repo's
zizmor/template-injectionalert in.github/workflows/codeql.yaml.What was wrong
The "Complete Security Scan" step spliced four
${{ steps.* }}expressions directly into thepwshscript body, so whatever they expand to is parsed as code, not data:Three of the four are GitHub-controlled outcome enums (
success/failure/cancelled/skipped). The fourth,steps.check-csharp.outputs.has-csharp, is a step output — the kind of value that can carry PR-influenced content.The fix
The values arrive through
env:and the script reads$env:NAME. Nothing interpolated is ever parsed as PowerShell. Behaviour is identical — same four variables, same four values, same downstream logic.This is repo-template's own fix, already on the template; this repository's
codeql.yamlpredates it.🤖 Generated with Claude Code
Closes #346