Skip to content

fix(publish-npm)!: pass command inputs through env to prevent template injection - #183

Open
PierreJeanjacquot wants to merge 1 commit into
mainfrom
fix/prevent-template-injection
Open

PierreJeanjacquot wants to merge 1 commit into
mainfrom
fix/prevent-template-injection

Conversation

@PierreJeanjacquot

@PierreJeanjacquot PierreJeanjacquot commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

fixes zizmor findings

BREAKING CHANGE: install-command, build-command, test-command, lint-command, type-check-command and format-check-command now only accept a single command with its arguments. Multi-line scripts, &&, ;, pipes, redirections, quotes and inline env assignments (FOO=bar cmd) are no longer supported; move such logic into an npm script and call it with npm run <script>.

@PierreJeanjacquot PierreJeanjacquot changed the title Fix/prevent template injection fix(publish-npm)!: pass command inputs through env to prevent template injection Oct 5, 2026
PierreJeanjacquot added a commit that referenced this pull request Oct 5, 2026
…nputs

The *-command inputs are meant to run arbitrary shell provided by the caller workflow, so the injection is by design. Fixing it the way zizmor suggests (passing the value through an env var and running it as ${VAR}) would stop bash from parsing the value as a script, so callers could only pass a single simple command: multi-line commands, &&, pipes and quotes would no longer work. This breaking change is deferred to a dedicated PR. (#183)
PierreJeanjacquot added a commit that referenced this pull request Oct 5, 2026
…nputs

The *-command inputs are meant to run arbitrary shell provided by the caller workflow, so the injection is by design. Fixing it the way zizmor suggests (passing the value through an env var and running it as ${VAR}) would stop bash from parsing the value as a script, so callers could only pass a single simple command: multi-line commands, &&, pipes and quotes would no longer work. This breaking change is deferred to a dedicated PR. (#183)
PierreJeanjacquot added a commit that referenced this pull request Oct 5, 2026
…nputs

The *-command inputs are meant to run arbitrary shell provided by the caller workflow, so the injection is by design. Fixing it the way zizmor suggests (passing the value through an env var and running it as ${VAR}) would stop bash from parsing the value as a script, so callers could only pass a single simple command: multi-line commands, &&, pipes and quotes would no longer work. This breaking change is deferred to a dedicated PR. (#183)
PierreJeanjacquot added a commit that referenced this pull request Oct 5, 2026
…nputs

The *-command inputs are meant to run arbitrary shell provided by the caller workflow, so the injection is by design. Fixing it the way zizmor suggests (passing the value through an env var and running it as ${VAR}) would stop bash from parsing the value as a script, so callers could only pass a single simple command: multi-line commands, &&, pipes and quotes would no longer work. This breaking change is deferred to a dedicated PR. (#183)
PierreJeanjacquot added a commit that referenced this pull request Oct 5, 2026
…nputs

The *-command inputs are meant to run arbitrary shell provided by the caller workflow, so the injection is by design. Fixing it the way zizmor suggests (passing the value through an env var and running it as ${VAR}) would stop bash from parsing the value as a script, so callers could only pass a single simple command: multi-line commands, &&, pipes and quotes would no longer work. This breaking change is deferred to a dedicated PR. (#183)
…e injection

The *-command inputs were expanded directly into run scripts, letting any value inject arbitrary shell. They are now passed through environment variables and expanded as `${VAR}`, so bash no longer parses them as a script.

BREAKING CHANGE: install-command, build-command, test-command, lint-command, type-check-command and format-check-command now only accept a single command with its arguments. Multi-line scripts, `&&`, `;`, pipes, redirections, quotes and inline env assignments (`FOO=bar cmd`) are no longer supported; move such logic into an npm script and call it with `npm run <script>`.
@PierreJeanjacquot
PierreJeanjacquot force-pushed the fix/prevent-template-injection branch from bfd7fac to fc1c9a7 Compare October 5, 2026 15:42
@PierreJeanjacquot
PierreJeanjacquot marked this pull request as ready for review October 5, 2026 15:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant