Skip to content

Commit d141fb1

Browse files
authored
Merge pull request #1480 from github/alert-autofix-1035
Potential fix for code scanning alert no. 1035: Environment variable built from user-controlled sources
2 parents 9573558 + 093b7a1 commit d141fb1

File tree

1 file changed

+3
-4
lines changed

1 file changed

+3
-4
lines changed

.github/workflows/publish-test-results.yml

Lines changed: 3 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -35,10 +35,9 @@ jobs:
3535
3636
- name: Extract PR Number
3737
run: |
38-
eventjson=`cat 'artifacts/Event File/event.json'`
39-
prnumber=`echo $(jq -r '.pull_request.number' <<< "$eventjson")`
40-
echo "PR_NUMBER=$(echo $prnumber | tr -cd '0-9')" >> $GITHUB_ENV
41-
38+
prnumber=$(jq -r '.pull_request.number' < 'artifacts/Event File/event.json')
39+
sanitized_prnumber=$(grep -E '^[0-9]+$' <<< "$prnumber")
40+
echo "PR_NUMBER=$sanitized_prnumber" >> "$GITHUB_ENV"
4241
- name: Publish Unit Test Results
4342
uses: EnricoMi/publish-unit-test-result-action@v2
4443
with:

0 commit comments

Comments
 (0)