Skip to content

fix(CI): use intermediate env variable to prevent TAG injection#2603

Merged
jiparis merged 1 commit intochainloop-dev:mainfrom
jiparis:ENG-311-gh
Dec 5, 2025
Merged

fix(CI): use intermediate env variable to prevent TAG injection#2603
jiparis merged 1 commit intochainloop-dev:mainfrom
jiparis:ENG-311-gh

Conversation

@jiparis
Copy link
Member

@jiparis jiparis commented Dec 5, 2025

Fixes release workflow to prevent ${{input.*}} usage from run: sections.

https://docs.github.com/en/actions/reference/security/secure-use#use-an-intermediate-environment-variable

Signed-off-by: Jose I. Paris <jiparis@chainloop.dev>
@jiparis jiparis requested review from javirln and migmartri December 5, 2025 10:48
@jiparis jiparis merged commit d8e5785 into chainloop-dev:main Dec 5, 2025
13 checks passed
@jiparis jiparis deleted the ENG-311-gh branch December 5, 2025 11:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants