Skip to content

SQSCANGHA-89 Attempt to fix command injection #186

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Apr 29, 2025

Conversation

henryju
Copy link
Member

@henryju henryju commented Apr 28, 2025

@henryju henryju force-pushed the jh/try_fix_command_injection branch 6 times, most recently from 87219cb to 9207a35 Compare April 28, 2025 14:34
It is unlikely to be a real concern, since an attacker having the possibility to edit a pipeline can easily execute any command, but at least our step won't be involved
@henryju henryju force-pushed the jh/try_fix_command_injection branch from 9207a35 to c999cf3 Compare April 28, 2025 14:37
@henryju henryju marked this pull request as ready for review April 28, 2025 14:44
@csaba-feher-sonarsource
Copy link
Contributor

I have ran through the test cases on a pipeline they look good:
Screenshot 2025-04-29 at 11 01 18
Screenshot 2025-04-29 at 10 59 41

Copy link
Contributor

@csaba-feher-sonarsource csaba-feher-sonarsource left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

I attached the test cases.

@henryju henryju merged commit be0a852 into master Apr 29, 2025
58 checks passed
@henryju henryju deleted the jh/try_fix_command_injection branch April 29, 2025 10:17
luketainton pushed a commit to luketainton/roboluke-tasks that referenced this pull request May 6, 2025
…0 (#349)

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [SonarSource/sonarqube-scan-action](https://github.com/SonarSource/sonarqube-scan-action) | action | minor | `v5.1.0` -> `v5.2.0` |

---

### Release Notes

<details>
<summary>SonarSource/sonarqube-scan-action (SonarSource/sonarqube-scan-action)</summary>

### [`v5.2.0`](https://github.com/SonarSource/sonarqube-scan-action/releases/tag/v5.2.0)

[Compare Source](SonarSource/sonarqube-scan-action@v5.1.0...v5.2.0)

##### What's Changed

-   SQSCANGHA-90 remove mend dead conf by [@&#8203;pierre-guillot-gh](https://github.com/pierre-guillot-gh) in SonarSource/sonarqube-scan-action#184
-   SQSCANGHA-89 Attempt to fix command injection by [@&#8203;henryju](https://github.com/henryju) in SonarSource/sonarqube-scan-action#186
-   SQSCANGHA-93 Fix madhead/semver-utils' version by [@&#8203;csaba-feher-sonarsource](https://github.com/csaba-feher-sonarsource) in SonarSource/sonarqube-scan-action#187
-   SQSCANGHA-94 Update version update logic by [@&#8203;csaba-feher-sonarsource](https://github.com/csaba-feher-sonarsource) in SonarSource/sonarqube-scan-action#188
-   SQSCANGHA-92 Validate scanner version by [@&#8203;csaba-feher-sonarsource](https://github.com/csaba-feher-sonarsource) in SonarSource/sonarqube-scan-action#189

**Full Changelog**: SonarSource/sonarqube-scan-action@v5...v5.2.0

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MC4wLjkiLCJ1cGRhdGVkSW5WZXIiOiI0MC4wLjkiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbInR5cGUvZGVwZW5kZW5jaWVzIl19-->

Reviewed-on: https://git.tainton.uk/repos/roboluke/pulls/349
Co-authored-by: Renovate [BOT] <[email protected]>
Co-committed-by: Renovate [BOT] <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants