Skip to content

Fix GitHub Actions shell injection vulnerability in setup-builder - #2

Open
fix-it-felix-sentry[bot] wants to merge 1 commit into
mainfrom
fix/eng-7584-github-actions-injection
Open

fix-it-felix-sentry[bot] wants to merge 1 commit into
mainfrom
fix/eng-7584-github-actions-injection

Conversation

@fix-it-felix-sentry

Copy link
Copy Markdown

Summary

This PR fixes a high-severity security finding where GitHub Actions input values were being directly interpolated in shell scripts, which could allow attackers to inject malicious code.

Changes

  • Added env: section to move inputs.rust-version and inputs.targets to environment variables (RUST_VERSION and TARGETS)
  • Replaced all direct ${{ inputs.* }} interpolations with properly quoted environment variable references
  • All variable references in shell commands are now properly quoted to prevent injection attacks

Security Impact

This fix prevents potential code injection attacks by ensuring that untrusted GitHub context data is only available as environment variables and properly quoted during use. This follows GitHub's security best practices for hardening GitHub Actions.

References

Testing

The GitHub Actions workflow will validate the syntax when this PR is opened. The action will be tested during the normal CI/CD pipeline execution.

Move GitHub Actions input values to environment variables to prevent
potential code injection attacks. This addresses a security finding
where untrusted user input from github context could be exploited
to inject malicious code into the runner.

Changes:
- Add env section with RUST_VERSION and TARGETS variables
- Replace all direct ${{ inputs.* }} interpolations with quoted env vars
- Properly quote all variable references in shell commands

Fixes: https://linear.app/getsentry/issue/ENG-7584
Parent: https://linear.app/getsentry/issue/VULN-1623

Co-Authored-By: Claude Sonnet 4.5 <[email protected]>
@linear-code

linear-code Bot commented May 2, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants