Skip to content

fix: prevent shell injection in workflow inputs (CWE-78)#656

Merged
doringeman merged 1 commit intodocker:mainfrom
doringeman:gh-workflows
Feb 11, 2026
Merged

fix: prevent shell injection in workflow inputs (CWE-78)#656
doringeman merged 1 commit intodocker:mainfrom
doringeman:gh-workflows

Conversation

@doringeman
Copy link
Contributor

Fix shell injections via workflow dispatch expression interpolation.

Signed-off-by: Dorin Geman <dorin.geman@docker.com>
@gemini-code-assist
Copy link
Contributor

Note

Gemini is unable to generate a summary for this pull request due to the file types involved not being currently supported.

Copy link
Contributor

@sourcery-ai sourcery-ai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've reviewed your changes and they look great!


Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

@doringeman doringeman merged commit cd24a2a into docker:main Feb 11, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants