Pass stacks selector via env var, not expression interpolation

Defense-in-depth from the security review: expression interpolation
into run: is pre-shell text substitution, so metacharacters in the
input would execute as script. Env-var expansion never re-parses shell
syntax; word-splitting for multiple selectors is preserved.
This commit is contained in:
Adam Moussa 2026-07-14 13:44:33 -04:00
parent fc86079df9
commit 18b602c975
No known key found for this signature in database

View file

@ -125,7 +125,12 @@ jobs:
- name: CDK deploy
working-directory: ${{ inputs.cdk-dir }}
run: npx -y cdk deploy ${{ inputs.stacks }} --require-approval never
# Env-var indirection (not inline expression interpolation) so shell
# metacharacters in the input are never parsed as script; unquoted
# $STACKS deliberately word-splits multiple selectors.
env:
STACKS: ${{ inputs.stacks }}
run: npx -y cdk deploy $STACKS --require-approval never
- name: Post-deploy script
if: ${{ inputs.post-deploy-script != '' }}