You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Document safe handling of file list outputs in workflows (#326)
Recommend passing *_files values through env: instead of interpolating them directly into run: scripts, and update README examples and CI workflows to follow that pattern.
Credits: https://github.com/tjswlsgg
Copy file name to clipboardExpand all lines: README.md
+12-2Lines changed: 12 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -67,6 +67,10 @@ For more scenarios see [examples](#examples) section.
67
67
68
68
## Notes
69
69
70
+
- **Security:** `${FILTER_NAME}_files` outputs contain filenames that may be attacker-influenced on pull requests.
71
+
Do not interpolate them directly into a `run:` script with `${{ ... }}`.
72
+
Pass the value through `env:` and reference the variable from the shell instead.
73
+
See [Custom processing of changed files](#custom-processing-of-changed-files).
70
74
- Paths expressions are evaluated using [picomatch](https://github.com/micromatch/picomatch) library.
71
75
Documentation for path expression format can be found on the project GitHub page.
72
76
- Picomatch [dot](https://github.com/micromatch/picomatch#options) option is set to true.
@@ -205,7 +209,7 @@ For more information, see [CHANGELOG](https://github.com/dorny/paths-filter/blob
205
209
- `'true'` - if **any** changed file matches **at least one** of the filter's rules and **none** of its negated rules
206
210
- `'false'` - if **no** changed file matches **at least one** of the filter's rules and **none** of its negated rules
207
211
- Each filter sets an output variable with the name `${FILTER_NAME}_count` to the count of matching files.
208
-
- If enabled, for each filter it sets an output variable with the name `${FILTER_NAME}_files`. It will contain a list of all files matching the filter.
212
+
- If enabled, for each filter it sets an output variable with the name `${FILTER_NAME}_files`. It will contain a list of all files matching the filter. Treat these values as untrusted when filenames can come from pull requests.
209
213
- `changes`- JSON array with names of all filters matching any of the changed files.
When passing file lists to shell commands, use `env:` as shown above. Do not write `${{ steps.filter.outputs.markdown_files }}` directly inside the `run:` script.
602
+
595
603
</details>
596
604
597
605
<details>
@@ -617,6 +625,8 @@ jobs:
617
625
files: ${{ steps.filter.outputs.changed_files }}
618
626
```
619
627
628
+
The `json` and `csv` formats are intended as structured data for scripts, programs, or other actions. Passing them to an action input as above is fine. Do not interpolate `json` or `csv` outputs directly into a `run:` script.
0 commit comments