Skip to content

security(ci): pass the resolved package version to apicompat through env - #365

Merged
Chris-Wolfgang merged 1 commit into
mainfrom
security/apicompat-template-injection
Sep 26, 2026
Merged

Chris-Wolfgang merged 1 commit into
mainfrom
security/apicompat-template-injection

Conversation

@Chris-Wolfgang

@Chris-Wolfgang Chris-Wolfgang commented Sep 23, 2026 •

Copy link
Copy Markdown
Owner

Second of Try-Pattern's two zizmor/template-injection alerts — .github/workflows/api-compat.yaml:95.

${{ steps.nuget.outputs.version }} was spliced straight into the bash script that downloads the previous package:

v='${{ steps.nuget.outputs.version }}'

The value is produced by the preceding step from NuGet's own version list, so it is not attacker-controlled today — but "a step output reaches a run: body by expansion" is exactly the shape the rule exists to catch, and closing it costs nothing. It now arrives as PREV_VERSION and the script reads it with normal quoting. Behaviour unchanged.

Stacked on #364 (the codeql.yaml fix). Merge that one first — this PR's base is that branch, so merging this from its own page before #364 lands would merge it into that branch rather than main.

🤖 Generated with Claude Code

Closes #347

Copilot AI lite review requested due to automatic review settings September 23, 2026 03:03

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The change is narrowly scoped and has no unresolved review issues.

Review effort: Lite
Findings: None

What changed in this PR

This PR hardens the API compatibility workflow against template injection by passing the resolved package version through an environment variable.

Changes:

  • Adds PREV_VERSION to the download step.
  • Uses quoted shell expansion for the package version.
File Description
.github/​workflows/​api-compat.yaml Safely passes the resolved package version to the Bash download script.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@Chris-Wolfgang
Chris-Wolfgang added this pull request to stack #369 September 26, 2026 16:57
@Chris-Wolfgang
Chris-Wolfgang force-pushed the security/apicompat-template-injection branch from 57d1a5e to 3368ad6 Compare September 26, 2026 17:45
Base automatically changed from security/codeql-template-injection to main September 26, 2026 19:19
zizmor's second template-injection finding in this repository: api-compat.yaml
spliced ${{ steps.nuget.outputs.version }} straight into the bash script that
downloads the previous package, so a step output was parsed as shell rather than
read as data. The value is produced by the preceding step from NuGet's own
version list, but "a step output reaches a run: body by expansion" is the shape
the rule exists to catch, and the fix costs nothing.

The version now arrives as PREV_VERSION and the script reads it with normal
quoting. Behaviour is unchanged.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@Chris-Wolfgang
Chris-Wolfgang force-pushed the security/apicompat-template-injection branch from 3368ad6 to 513d9e2 Compare September 26, 2026 19:19
@Chris-Wolfgang
Chris-Wolfgang merged commit 885144d into main Sep 26, 2026
20 checks passed
@Chris-Wolfgang
Chris-Wolfgang deleted the security/apicompat-template-injection branch September 26, 2026 19:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Alert: zizmor zizmor/template-injection in .github/workflows/api-compat.yaml

2 participants