Skip to content

Conversation

@lociko
Copy link
Contributor

@lociko lociko commented Mar 28, 2025

  • This change is worth documenting at https://docs.all-hands.dev/
  • Include this change in the Release Notes. If checked, you must provide an end-user friendly description for your change below

Fixed a potential security vulnerability in GitHub Actions workflows that could allow command injection through user inputs such as PR review content.

@lociko lociko marked this pull request as ready for review March 28, 2025 10:23
Copy link
Collaborator

@xingyaoww xingyaoww left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! Thanks!

@xingyaoww xingyaoww merged commit 4a2045e into OpenHands:main Apr 1, 2025
14 checks passed
doew pushed a commit to doew/OpenHands that referenced this pull request Apr 2, 2025
…nput like review body and gti (OpenHands#7569)

Co-authored-by: Vasyl Spachynskyi <vasyl.spachynskyi@dataart.com>
shabbir-shakudo pushed a commit to devsentient/OpenHands that referenced this pull request Jul 15, 2025
…nput like review body and gti (OpenHands#7569)

Co-authored-by: Vasyl Spachynskyi <vasyl.spachynskyi@dataart.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants