Skip to content

Commit 90ffa63

Browse files
authored
Merge pull request #1451 from github/mulana/security-issue-environment-variable-injection
Fix environment variable injection vulnerability in publish-test-results workflow
2 parents b380004 + 817ff79 commit 90ffa63

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

.github/workflows/publish-test-results.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,7 @@ jobs:
3737
run: |
3838
eventjson=`cat 'artifacts/Event File/event.json'`
3939
prnumber=`echo $(jq -r '.pull_request.number' <<< "$eventjson")`
40-
echo "PR_NUMBER=$(echo $prnumber | tr -cd '[0-9]')" >> $GITHUB_ENV
40+
echo "PR_NUMBER=$(echo $prnumber | tr -cd '0-9')" >> $GITHUB_ENV
4141
4242
- name: Publish Unit Test Results
4343
uses: EnricoMi/publish-unit-test-result-action@v2

0 commit comments

Comments
 (0)