fix: prevent script injection in test coverage workflow [WPB-27114] - #8159
Open
screendriver wants to merge 1 commit into
Open
fix: prevent script injection in test coverage workflow [WPB-27114]#8159screendriver wants to merge 1 commit into
screendriver wants to merge 1 commit into
Conversation
Route dispatch tag values through environment variables before shell use. Quote all untrusted expansions and GitHub output paths, remove the redundant tag output and reject whitespace in parsed tags while preserving workflow behavior and permissions.
screendriver
requested review from
arjita-mitra,
e-maad and
zskhan
and
a lite review from Copilot
and removed request for
Copilot
September 3, 2026 09:26
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pull Request
Summary
Fix unsafe interpolation of the manually supplied
tagworkflow input into shell scripts intest-coverage-report.yml.The workflow now passes untrusted and derived values through step-level environment variables before using them in
run:steps, rather than interpolating GitHub Actions expressions directly into the generated shell source.This covers the original Semgrep finding as well as the downstream uses of the parsed tag, package, and version values.
No workflow permissions or behavior are intentionally changed.
Security Checklist (required)
Accessibility (required)
Standards Acknowledgement (required)
Screenshots or demo (if the user interface changed)
Notes for reviewers