.github/.github
Adam Moussa 7ece0b6c2a
fix(ci): pass deploy inputs via env, not shell interpolation
GitHub Actions expressions are substituted into a run body as text
before bash parses it, so a value carrying a quote, a command
substitution, or a newline becomes shell syntax rather than data.

cd-sam.yaml interpolated the parameter-overrides secret straight into
a shell test and an assignment, putting secret material into the script
body. cd-cdk.yaml interpolated the caller-supplied post-deploy-script
input into a bash invocation, which is caller-controlled command
injection rather than secret exposure.

Both now use env-var indirection, matching the STACKS precedent in the
CDK deploy step. PARAM_OVERRIDES is deliberately left unquoted at the
point of use: parameter-overrides carries multiple Key=Value pairs that
must reach sam deploy as separate argv entries, so quoting it would
collapse every override into one argument and break deploys that use
it. POST_DEPLOY_SCRIPT is a single path and is quoted.

Behaviour is otherwise unchanged. An empty parameter-overrides still
produces no --parameter-overrides flag at all, and an empty
post-deploy-script is still skipped by the step-level if condition,
which is a workflow expression and not shell.
2026-07-28 12:35:00 -04:00
..
ISSUE_TEMPLATE INFRA-58 INFRA-59: org starter workflows + issue templates (#43) 2026-06-05 17:26:16 -04:00
workflows fix(ci): pass deploy inputs via env, not shell interpolation 2026-07-28 12:35:00 -04:00
CODEOWNERS Add org-wide default CODEOWNERS (#37) 2026-06-05 12:11:40 -04:00
dependabot.yml Add org-wide reusable PR labeler (INFRA-56) (#50) 2026-06-11 13:34:39 -04:00
PULL_REQUEST_TEMPLATE.md Add dependency-review workflow and Sea Haven PR checklist (#36) 2026-06-05 12:11:36 -04:00