Merge pull request #102 from Sea-Haven-Industries/fix/workflow-expression-injection

fix(ci): pass deploy inputs via env, not shell interpolation
This commit is contained in:
Adam Moussa 2026-07-28 12:53:28 -04:00 • committed by GitHub
commit 62254a7837
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 13 additions and 3 deletions

View file

@ -134,7 +134,12 @@ jobs:
- name: Post-deploy script
if: ${{ inputs.post-deploy-script != '' }}
run: bash ${{ inputs.post-deploy-script }}
# Env-var indirection (not inline expression interpolation) so shell
# metacharacters in the input are never parsed as script; the input is a
# single script path, so $POST_DEPLOY_SCRIPT is quoted (no word-split).
env:
POST_DEPLOY_SCRIPT: ${{ inputs.post-deploy-script }}
run: bash "$POST_DEPLOY_SCRIPT"
- name: Post-deploy health check
if: ${{ inputs.stack-name != '' }}

View file

@ -80,10 +80,15 @@ jobs:
run: sam build --template ${{ inputs.sam-template }}
- name: SAM deploy
# Env-var indirection (not inline expression interpolation) so shell
# metacharacters in the secret are never parsed as script; unquoted
# $PARAM_OVERRIDES deliberately word-splits multiple Key=Value pairs.
env:
PARAM_OVERRIDES: ${{ secrets.parameter-overrides }}
run: |
PARAMS=""
if [ -n "${{ secrets.parameter-overrides }}" ]; then
PARAMS="--parameter-overrides ${{ secrets.parameter-overrides }}"
if [ -n "$PARAM_OVERRIDES" ]; then
PARAMS="--parameter-overrides $PARAM_OVERRIDES"
fi
sam deploy \
--stack-name ${{ inputs.stack-name }} \