Skip to content

feat: refine action for enhanced security#40

Merged
tdruez merged 9 commits intomainfrom
workflows-security
Mar 27, 2026
Merged

feat: refine action for enhanced security#40
tdruez merged 9 commits intomainfrom
workflows-security

Conversation

@tdruez
Copy link
Copy Markdown
Contributor

@tdruez tdruez commented Mar 27, 2026

Changes

  • Move ${{ inputs.* }} into env: mappings
  • Remove eval in compliance step
  • Add path traversal guard
  • Add URL scheme validation
  • Harden shell quoting, quote $GITHUB_ENV and other variable expansions consistently

tdruez added 9 commits March 27, 2026 08:54
Signed-off-by: tdruez <tdruez@aboutcode.org>
Signed-off-by: tdruez <tdruez@aboutcode.org>
Signed-off-by: tdruez <tdruez@aboutcode.org>
Signed-off-by: tdruez <tdruez@aboutcode.org>
Signed-off-by: tdruez <tdruez@aboutcode.org>
Signed-off-by: tdruez <tdruez@aboutcode.org>
Signed-off-by: tdruez <tdruez@aboutcode.org>
Signed-off-by: tdruez <tdruez@aboutcode.org>
Signed-off-by: tdruez <tdruez@aboutcode.org>
@tdruez tdruez changed the title feat: action security feat: refine action for enhanced security Mar 27, 2026
@tdruez tdruez merged commit 6e900c9 into main Mar 27, 2026
8 checks passed
@tdruez tdruez deleted the workflows-security branch March 27, 2026 11:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant