From a842d79cae74ef0ff46d7dee2fe7f124df547461 Mon Sep 17 00:00:00 2001 From: Willie Ruemmele Date: Thu, 24 Sep 2026 09:14:49 -0600 Subject: [PATCH 1/3] fix: prevent command injection in nightly workflow @W-24289114@ Move user-controlled `inputs.only` from direct GitHub expression expansion in `run:` blocks to `env:` blocks, where the value becomes a shell variable instead of inline script text. Add input validation to reject values containing shell metacharacters. --- .github/workflows/make-pr-for-nightly.yml | 20 ++++++++++++++++---- 1 file changed, 16 insertions(+), 4 deletions(-) diff --git a/.github/workflows/make-pr-for-nightly.yml b/.github/workflows/make-pr-for-nightly.yml index 8cb1eded3..88ad92e94 100644 --- a/.github/workflows/make-pr-for-nightly.yml +++ b/.github/workflows/make-pr-for-nightly.yml @@ -89,15 +89,27 @@ jobs: - name: Fetch all branches run: git fetch - # --only input using a "ternary-ish": https://github.com/actions/runner/issues/409#issuecomment-752775072 - # ${{ x && 'ifTrue' || 'ifFalse' }} + - name: Validate inputs + if: ${{ inputs.only != '' }} + shell: bash + run: | + if [[ ! "$INPUT_ONLY" =~ ^[@a-zA-Z0-9/_,.~-]+$ ]]; then + echo "::error::'only' input contains invalid characters. Must be a comma-separated list of package names." + exit 1 + fi + env: + INPUT_ONLY: ${{ inputs.only }} - name: Build nightly PR (minor) - run: sf-release cli:release:build --start-from-github-ref main ${{ inputs.only && format('--only {0}', inputs.only) || '' }} --label nightly-automerge --release-channel nightly + run: sf-release cli:release:build --start-from-github-ref main $ONLY_FLAG --label nightly-automerge --release-channel nightly + env: + ONLY_FLAG: ${{ inputs.only && format('--only {0}', inputs.only) || '' }} # If the package.json 'minor' IS EQUAL TO the latest-rc 'minor', we want to bump 'minor' if: ${{ fromJSON(steps.package-json-semver-info.outputs.minor) == fromJSON(steps.latest-rc-semver-info.outputs.minor) }} - name: Build nightly PR (patch) - run: sf-release cli:release:build --start-from-github-ref main --patch ${{ inputs.only && format('--only {0}', inputs.only) || '' }} --label nightly-automerge --release-channel nightly + run: sf-release cli:release:build --start-from-github-ref main --patch $ONLY_FLAG --label nightly-automerge --release-channel nightly + env: + ONLY_FLAG: ${{ inputs.only && format('--only {0}', inputs.only) || '' }} # If the package.json 'minor' IS GREATER THAN the latest-rc 'minor', we want to bump 'patch' if: ${{ fromJSON(steps.package-json-semver-info.outputs.minor) > fromJSON(steps.latest-rc-semver-info.outputs.minor) }} From dcec65f1ea7eb3296857b72340dc97fb8c410c7c Mon Sep 17 00:00:00 2001 From: Willie Ruemmele Date: Thu, 24 Sep 2026 09:19:33 -0600 Subject: [PATCH 2/3] chore: add comments explaining intentional word-splitting --- .github/workflows/make-pr-for-nightly.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.github/workflows/make-pr-for-nightly.yml b/.github/workflows/make-pr-for-nightly.yml index 88ad92e94..6554a20c9 100644 --- a/.github/workflows/make-pr-for-nightly.yml +++ b/.github/workflows/make-pr-for-nightly.yml @@ -101,6 +101,7 @@ jobs: INPUT_ONLY: ${{ inputs.only }} - name: Build nightly PR (minor) + # $ONLY_FLAG is intentionally unquoted — it must word-split into two args (--only ) run: sf-release cli:release:build --start-from-github-ref main $ONLY_FLAG --label nightly-automerge --release-channel nightly env: ONLY_FLAG: ${{ inputs.only && format('--only {0}', inputs.only) || '' }} @@ -108,6 +109,7 @@ jobs: if: ${{ fromJSON(steps.package-json-semver-info.outputs.minor) == fromJSON(steps.latest-rc-semver-info.outputs.minor) }} - name: Build nightly PR (patch) + # $ONLY_FLAG is intentionally unquoted — it must word-split into two args (--only ) run: sf-release cli:release:build --start-from-github-ref main --patch $ONLY_FLAG --label nightly-automerge --release-channel nightly env: ONLY_FLAG: ${{ inputs.only && format('--only {0}', inputs.only) || '' }} From 9447729c5d029b1650adc632a770d67ba91a14b5 Mon Sep 17 00:00:00 2001 From: Willie Ruemmele Date: Thu, 24 Sep 2026 13:06:49 -0600 Subject: [PATCH 3/3] fix: remove ~ from input validation allowlist No packages passed to --only will contain a tilde. --- .github/workflows/make-pr-for-nightly.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/make-pr-for-nightly.yml b/.github/workflows/make-pr-for-nightly.yml index 6554a20c9..2b25847a4 100644 --- a/.github/workflows/make-pr-for-nightly.yml +++ b/.github/workflows/make-pr-for-nightly.yml @@ -93,7 +93,7 @@ jobs: if: ${{ inputs.only != '' }} shell: bash run: | - if [[ ! "$INPUT_ONLY" =~ ^[@a-zA-Z0-9/_,.~-]+$ ]]; then + if [[ ! "$INPUT_ONLY" =~ ^[@a-zA-Z0-9/_,.-]+$ ]]; then echo "::error::'only' input contains invalid characters. Must be a comma-separated list of package names." exit 1 fi