mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 07:03:11 +00:00
GitHub Actions expressions are substituted into a run body as text before bash parses it, so a value carrying a quote, a command substitution, or a newline becomes shell syntax rather than data. cd-sam.yaml interpolated the parameter-overrides secret straight into a shell test and an assignment, putting secret material into the script body. cd-cdk.yaml interpolated the caller-supplied post-deploy-script input into a bash invocation, which is caller-controlled command injection rather than secret exposure. Both now use env-var indirection, matching the STACKS precedent in the CDK deploy step. PARAM_OVERRIDES is deliberately left unquoted at the point of use: parameter-overrides carries multiple Key=Value pairs that must reach sam deploy as separate argv entries, so quoting it would collapse every override into one argument and break deploys that use it. POST_DEPLOY_SCRIPT is a single path and is quoted. Behaviour is otherwise unchanged. An empty parameter-overrides still produces no --parameter-overrides flag at all, and an empty post-deploy-script is still skipped by the step-level if condition, which is a workflow expression and not shell. |
||
|---|---|---|
| .. | ||
| ISSUE_TEMPLATE | ||
| workflows | ||
| CODEOWNERS | ||
| dependabot.yml | ||
| PULL_REQUEST_TEMPLATE.md | ||