Skip to content

Conversation

Fdawgs
Copy link
Member

@Fdawgs Fdawgs commented Aug 15, 2025

This was covered in the GitHub Secure Open Source Fund program that Fastify participated in.
See https://securitylab.github.com/resources/github-actions-untrusted-input/ for supporting documentation.

Checklist

Copy link
Member

@gurgunday gurgunday left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@Fdawgs Fdawgs requested a review from Eomm August 15, 2025 08:41
Copy link
Member

@RafaelGSS RafaelGSS left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

IIRC the matrix.node-version isn't a untrusted input as we have the versions fixed in the workflow.

Anyway, LGTM

@Fdawgs
Copy link
Member Author

Fdawgs commented Aug 17, 2025

IIRC the matrix.node-version isn't a untrusted input as we have the versions fixed in the workflow.

That was just to stop the codeql false positives constantly popping up. 😬

Copy link
Contributor

@Uzlopak Uzlopak left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Copy link
Member

@mcollina mcollina left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@Uzlopak Uzlopak merged commit c898d5e into main Aug 17, 2025
3 checks passed
@Uzlopak Uzlopak deleted the fix/code-injection branch August 17, 2025 08:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

6 participants