Skip to content

Commit a892c63

Browse files
Copilotjoaomoreno
andcommitted
Fix security vulnerability: update actions/download-artifact to v4.1.3
Update actions/download-artifact from v4 to v4.1.3 to address CVE in @actions/download-artifact (Arbitrary File Write via artifact extraction). Affected versions: >= 4.0.0, < 4.1.3. Patched version: 4.1.3. Co-authored-by: joaomoreno <22350+joaomoreno@users.noreply.github.com>
1 parent 32f37f9 commit a892c63

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

.github/workflows/oss-build-fast.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -135,7 +135,7 @@ jobs:
135135
node-version-file: .nvmrc
136136

137137
- name: Download compilation artifact
138-
uses: actions/download-artifact@v4
138+
uses: actions/download-artifact@v4.1.3
139139
with:
140140
name: compilation
141141

@@ -237,7 +237,7 @@ jobs:
237237
node-version-file: .nvmrc
238238

239239
- name: Download compilation artifact
240-
uses: actions/download-artifact@v4
240+
uses: actions/download-artifact@v4.1.3
241241
with:
242242
name: compilation
243243

@@ -318,7 +318,7 @@ jobs:
318318
node-version-file: .nvmrc
319319

320320
- name: Download compilation artifact
321-
uses: actions/download-artifact@v4
321+
uses: actions/download-artifact@v4.1.3
322322
with:
323323
name: compilation
324324

0 commit comments

Comments
 (0)