Skip to content

security(ci): pass step outcomes to the CodeQL summary through env, not template expansion - #364

Merged
Chris-Wolfgang merged 1 commit into
mainfrom
security/codeql-template-injection
Sep 26, 2026
Merged

Chris-Wolfgang merged 1 commit into
mainfrom
security/codeql-template-injection

Conversation

@Chris-Wolfgang

@Chris-Wolfgang Chris-Wolfgang commented Sep 23, 2026 •

Copy link
Copy Markdown
Owner

Closes the repo's zizmor/template-injection alert in .github/workflows/codeql.yaml.

What was wrong

The "Complete Security Scan" step spliced four ${{ steps.* }} expressions directly into the pwsh script body, so whatever they expand to is parsed as code, not data:

run: |
  $hasCsharp = "${{ steps.check-csharp.outputs.has-csharp }}"

Three of the four are GitHub-controlled outcome enums (success/failure/cancelled/skipped). The fourth, steps.check-csharp.outputs.has-csharp, is a step output — the kind of value that can carry PR-influenced content.

The fix

The values arrive through env: and the script reads $env:NAME. Nothing interpolated is ever parsed as PowerShell. Behaviour is identical — same four variables, same four values, same downstream logic.

This is repo-template's own fix, already on the template; this repository's codeql.yaml predates it.

🤖 Generated with Claude Code

Closes #346

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The workflow safely handles step values without unresolved blocking issues.

Review effort: Lite
Findings: None

What changed in this PR

Updates the CodeQL workflow to prevent template-injection risks while preserving scan behavior.

Changes:

  • Passes step values through environment variables.
  • Reads them from PowerShell environment variables.
  • Preserves existing status logic.
File Description
.github/​workflows/​codeql.yaml Secures CodeQL summary value handling.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@Chris-Wolfgang
Chris-Wolfgang added this pull request to stack #369 September 26, 2026 16:57
…ot template expansion

zizmor reports template-injection against codeql.yaml's "Complete Security Scan"
step: four ${{ steps.* }} expressions are spliced straight into the pwsh script
body, so whatever they expand to becomes code rather than data. Three of them are
GitHub-controlled outcome enums, but steps.check-csharp.outputs.has-csharp is a
step output - exactly the kind of value that can carry PR-influenced content.

repo-template already fixed this; this repository's codeql.yaml predates it. The
four values now arrive as environment variables and the script reads $env:NAME,
so nothing attacker-influenced is ever parsed as PowerShell. Behaviour is
unchanged: the same four variables hold the same four values.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@Chris-Wolfgang
Chris-Wolfgang force-pushed the security/codeql-template-injection branch from 7fbd8c9 to e339483 Compare September 26, 2026 17:45
@Chris-Wolfgang
Chris-Wolfgang merged commit 4ffcd3e into main Sep 26, 2026
18 checks passed
@Chris-Wolfgang
Chris-Wolfgang deleted the security/codeql-template-injection branch September 26, 2026 19:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Alert: zizmor zizmor/template-injection in .github/workflows/codeql.yaml

2 participants