opencv / opencv/ci-gha-workflow

Security risks in OpenCV actions?

Open
#85 1 comment 1 reaction 1 assignee View on GitHub

@avdivan is already working on this.

Since Oct 30, 2025.

Dominant language
Python
Stars
24
Forks
34
Avg merge
2d 9h
Merged PRs (30d)
14

Description

https://github.com/opencv/ci-gha-workflow/blob/8578610d78e194f89f17c0939116300ae7c45983/.github/workflows/OCV-Contrib-PR-3.4-ARM64.yaml#L57-L60

Is it safe to use injections here via env var? I suppose once SOURCE_BRANCH_NAME and other env vars are created, they should be referenced simply as $SOURCE_BRANCH_NAME, otherwise it may not have proper effect.

Please, see Remediation section as a reference.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.