Skip to content

ci(pr-review-companion): access step outputs via env vars #26677

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Apr 3, 2025

Conversation

caugner
Copy link
Contributor

@caugner caugner commented Apr 3, 2025

Description

Updates the pr-review-companion to access step outputs via environment variables.

Motivation

Reduces the risk of command injection.

Additional details

Related issues and pull requests

Same as:

Follow-up of:

Reduces the risk of command injection.
@caugner caugner requested a review from bsmth April 3, 2025 08:55
@caugner caugner requested a review from a team as a code owner April 3, 2025 08:55
@github-actions github-actions bot added the system Infrastructure and configuration for the project label Apr 3, 2025
Copy link
Member

@bsmth bsmth left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks!

@caugner caugner merged commit 17d8565 into main Apr 3, 2025
10 checks passed
@caugner caugner deleted the avoid-direct-outputs-access branch April 3, 2025 10:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
system Infrastructure and configuration for the project
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants