Skip to content

Mitigate script injection attack in snyk/actions/setup#157

Merged
dotkas merged 1 commit intosnyk:masterfrom
fabasoad:fix/shell-injection
Jul 1, 2025
Merged

Mitigate script injection attack in snyk/actions/setup#157
dotkas merged 1 commit intosnyk:masterfrom
fabasoad:fix/shell-injection

Conversation

@fabasoad
Copy link
Copy Markdown
Contributor

@fabasoad fabasoad commented Jun 30, 2025

It is possible to perform script injection via inputs in snyk/actions/setup GitHub Action. This fix mitigates it. More details here.

@fabasoad fabasoad requested a review from a team as a code owner June 30, 2025 21:24
@snyk-io
Copy link
Copy Markdown

snyk-io bot commented Jun 30, 2025

🎉 Snyk checks have passed. No issues have been found so far.

code/snyk check is complete. No issues have been found. (View Details)

@fabasoad fabasoad changed the title Mitigate script injection attack Mitigate script injection attack in snyk/actions/setup Jun 30, 2025
@dotkas dotkas merged commit aa6e70d into snyk:master Jul 1, 2025
6 checks passed
@dotkas
Copy link
Copy Markdown
Contributor

dotkas commented Jul 1, 2025

Thanks for your contributions @fabasoad 🙏🏻

@fabasoad fabasoad deleted the fix/shell-injection branch July 1, 2025 09:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants