Skip to content

Commit 526da67

Browse files
chore: [SECURITY-1357] standardize string quotes (#2627)
chore: standardize string quotes in workflow https://docs.github.com/en/actions/reference/security/secure-use#good-practices-for-mitigating-script-injection-attacks
1 parent 52f739a commit 526da67

1 file changed

Lines changed: 7 additions & 3 deletions

File tree

.github/workflows/failure-notification.yaml

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -31,11 +31,15 @@ jobs:
3131

3232
- name: Create Issue
3333
uses: actions/github-script@v7
34+
env:
35+
WORKFLOW_NAME: ${{ inputs.workflow_name }}
36+
JOB_NAME: ${{ inputs.job_name }}
37+
FAILURE_REASON: ${{ inputs.failure_reason }}
3438
with:
3539
script: |
36-
const workflowName = '${{ inputs.workflow_name }}';
37-
const jobName = '${{ inputs.job_name }}';
38-
const failureReason = '${{ inputs.failure_reason }}';
40+
const workflowName = process.env.WORKFLOW_NAME;
41+
const jobName = process.env.JOB_NAME;
42+
const failureReason = process.env.FAILURE_REASON;
3943
const runUrl = `${context.payload.repository.html_url}/actions/runs/${context.runId}`;
4044
const commitSha = context.sha;
4145
const commitUrl = `${context.payload.repository.html_url}/commit/${commitSha}`;

0 commit comments

Comments
 (0)