opencv / opencv/ci-gha-workflow
Security risks in OpenCV actions?
Open
@avdivan is already working on this.
Since Oct 30, 2025.
- Dominant language
- Python
- Stars
- 24
- Forks
- 34
- Avg merge
- 2d 9h
- Merged PRs (30d)
- 14
Description
Is it safe to use injections here via env var? I suppose once SOURCE_BRANCH_NAME and other env vars are created, they should be referenced simply as $SOURCE_BRANCH_NAME, otherwise it may not have proper effect.
Please, see Remediation section as a reference.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.