From 18b602c975c1755ee672bbd66d06fdddcebccfe0 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Tue, 14 Jul 2026 13:44:33 -0400 Subject: [PATCH] Pass stacks selector via env var, not expression interpolation Defense-in-depth from the security review: expression interpolation into run: is pre-shell text substitution, so metacharacters in the input would execute as script. Env-var expansion never re-parses shell syntax; word-splitting for multiple selectors is preserved. --- .github/workflows/cd-cdk.yaml | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/.github/workflows/cd-cdk.yaml b/.github/workflows/cd-cdk.yaml index 4d97898..82d1d21 100644 --- a/.github/workflows/cd-cdk.yaml +++ b/.github/workflows/cd-cdk.yaml @@ -125,7 +125,12 @@ jobs: - name: CDK deploy working-directory: ${{ inputs.cdk-dir }} - run: npx -y cdk deploy ${{ inputs.stacks }} --require-approval never + # Env-var indirection (not inline expression interpolation) so shell + # metacharacters in the input are never parsed as script; unquoted + # $STACKS deliberately word-splits multiple selectors. + env: + STACKS: ${{ inputs.stacks }} + run: npx -y cdk deploy $STACKS --require-approval never - name: Post-deploy script if: ${{ inputs.post-deploy-script != '' }}