Skip to content

ci006 safe verification#3571

Closed
mickeyjoes wants to merge 1 commit intosegmentio:mainfrom
mickeyjoes:ci006-runner-proof
Closed

ci006 safe verification#3571
mickeyjoes wants to merge 1 commit intosegmentio:mainfrom
mickeyjoes:ci006-runner-proof

Conversation

@mickeyjoes
Copy link

Safe verification PR for command-substitution in required-field-check workflow. Uses marker payload only.

Copilot AI review requested due to automatic review settings February 4, 2026 18:28
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adds a security verification test file to detect command injection vulnerabilities in the required-field-check workflow. The file uses a marker payload with command substitution in its filename ($(printf CI006_MARKER>&2)) to verify that the workflow safely handles potentially malicious filenames.

Changes:

  • Added a proof-of-concept test file with command substitution in its filename to verify workflow security

@mickeyjoes
Copy link
Author

Closing per triage request; I will reproduce on my own fork and provide runner-log evidence there.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants