Skip to content

Fix zizmor "code injection via template expansion"#2784

Merged
henryiii merged 4 commits intomainfrom
inline-parameter
Mar 27, 2026
Merged

Fix zizmor "code injection via template expansion"#2784
henryiii merged 4 commits intomainfrom
inline-parameter

Conversation

@joerick
Copy link
Contributor

@joerick joerick commented Mar 16, 2026

  • Refactor action.yml to avoid template expansion, composing command line in Python
  • Remove more template expansion
  • Make a string quoting that's compatible with pwsh
@joerick joerick marked this pull request as ready for review March 16, 2026 23:10
@henryiii henryiii merged commit 6111948 into main Mar 27, 2026
45 checks passed
@henryiii henryiii deleted the inline-parameter branch March 27, 2026 15:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

3 participants