mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-10-02 06:13:17 +00:00
Pass stacks selector via env var, not expression interpolation
Defense-in-depth from the security review: expression interpolation into run: is pre-shell text substitution, so metacharacters in the input would execute as script. Env-var expansion never re-parses shell syntax; word-splitting for multiple selectors is preserved.
This commit is contained in:
parent
fc86079df9
commit
18b602c975
1 changed files with 6 additions and 1 deletions
7
.github/workflows/cd-cdk.yaml
vendored
7
.github/workflows/cd-cdk.yaml
vendored
|
|
@ -125,7 +125,12 @@ jobs:
|
||||||
|
|
||||||
- name: CDK deploy
|
- name: CDK deploy
|
||||||
working-directory: ${{ inputs.cdk-dir }}
|
working-directory: ${{ inputs.cdk-dir }}
|
||||||
run: npx -y cdk deploy ${{ inputs.stacks }} --require-approval never
|
# Env-var indirection (not inline expression interpolation) so shell
|
||||||
|
# metacharacters in the input are never parsed as script; unquoted
|
||||||
|
# $STACKS deliberately word-splits multiple selectors.
|
||||||
|
env:
|
||||||
|
STACKS: ${{ inputs.stacks }}
|
||||||
|
run: npx -y cdk deploy $STACKS --require-approval never
|
||||||
|
|
||||||
- name: Post-deploy script
|
- name: Post-deploy script
|
||||||
if: ${{ inputs.post-deploy-script != '' }}
|
if: ${{ inputs.post-deploy-script != '' }}
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue