audit workflows for string injection vulns
Open
ci-scripts
enhancement
- Dominant language
- JavaScript
- Stars
- 3
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Description
Anywhere there's `${{ something }}` is a place where Bad Shit can happen. Some of them are Fine, others Aren't. Ideally I should extract more from the `github` context object that gets injected into github JS workflows, so that strings are already strings and not something I need to inject into quotes!
Do an audit pass before shipping.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.