fix: pass GitHub event context via env vars in reusable workflows#87
Merged
crowecawcaw merged 1 commit intoJun 26, 2026
Merged
Conversation
Move github.event.* interpolations (pull_request.number, event.action, repository.name) out of inline run: scripts and into env: blocks so they are referenced as shell variables rather than templated into script text. Resolves ACAT script-injection finding 540a0df3-f469-4f97-ad17-b1ed5d37023d (Bea-57529). These values are GitHub-controlled and structurally constrained, so this is defense-in-depth, but it clears the scanner pattern permanently. Signed-off-by: Stephen Crowe <6042774+crowecawcaw@users.noreply.github.com>
crowecawcaw
force-pushed
the
fix-actions-script-injection
branch
from
June 26, 2026 20:37
7ab2acb to
0b2927d
Compare
andychoquette
approved these changes
Jun 26, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What was the problem/requirement? (What/Why)
Some github event data is interpolated into inline scripts.
What was the solution? (How)
Move
github.event.*interpolations (pull_request.number, event.action, repository.name) out of inline run: scripts and into env: blocks so they are referenced as shell variables rather than templated into script text.What is the impact of this change?
Avoids possibility of some script injections. Not really an issue for this particular use case, but can trip up security scanners.
How was this change tested?
Triggered an action that uses this mechanism in my fork: https://github.com/crowecawcaw/deadline-cloud.github/actions/runs/28263554472/job/83744704079
Was this change documented?
n/a
Is this a breaking change?
No
By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.