axodotdev / axodotdev/harbor

audit workflows for string injection vulns

Open
#12 0 comments 0 reactions 0 assignees View on GitHub
ci-scripts enhancement
Dominant language
JavaScript
Stars
3
Forks
1
PR merge metrics
No merged PRs in 30d

Description

Anywhere there's `${{ something }}` is a place where Bad Shit can happen. Some of them are Fine, others Aren't. Ideally I should extract more from the `github` context object that gets injected into github JS workflows, so that strings are already strings and not something I need to inject into quotes!

Do an audit pass before shipping.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.