Security: restrict workflow context#3124
Conversation
Co-Authored-By: polarathene <[email protected]>
polarathene
left a comment
There was a problem hiding this comment.
LGTM 👍
I'm not sure if anyone outside your organization members (and myself) can view the advisory linked. That might require me to update the "Affected products" section, but I'm not sure what I'd put there 😅
The change suggestions added from this review aren't too important, but often a good practice to refer to shell/env variables with ${ + }.
|
You should be good to merge this PR as a fix, but I'll ping @pwntester from GHSL and he'll let you know if anything else needs to be addressed 👍 |
|
Just to chime in about the recent change (that I didn't notice with my review, whoops! 😅 ), in the referenced advisory (not publicly viewable) I had shown the The advisory discussed a few options and I could probably have explained them more clearly. |
Related to: GHSA-mjw5-7mvp-34wc