Open renovate[bot] opened 2 months ago
This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.
Thanks for opening an issue! Make sure you've followed CONTRIBUTING.md.
Is your PR ready for review and processing? Mark the PR ready by including #pr-ready
in a comment.
If you still have work to do, even after marking this ready. Put the PR on hold by including #pr-onhold
in a comment.
Thanks for the PR!
This section of the codebase is owner by https://github.com/AlexRogalskiy/ - if they write a comment saying "LGTM" then it will be merged.
New and removed dependencies detected. Learn more about Socket for GitHub ↗︎
Package | New capabilities | Transitives | Size | Publisher |
---|---|---|---|---|
npm/@actions/http-client@2.2.1 | network | 0 |
70.3 kB | thboop |
npm/@fastify/busboy@2.1.1 | None | 0 |
80.2 kB | gurgunday |
npm/tunnel@0.0.6 | environment, network | 0 |
64.9 kB | koichik |
npm/undici@5.28.4 | environment, network, unsafe | 0 |
1.17 MB | matteo.collina |
🚮 Removed packages: npm/whatwg-encoding@1.0.5, npm/whatwg-mimetype@2.3.0, npm/whatwg-url@8.4.0, npm/which@1.3.1
This PR contains the following updates:
1.2.6
->1.9.1
GitHub Vulnerability Alerts
CVE-2022-35954
Impact
The
core.exportVariable
function uses a well known delimiter that attackers can use to break out of that specific variable and assign values to other arbitrary variables. Workflows that write untrusted values to theGITHUB_ENV
file may cause the path or other environment variables to be modified without the intention of the workflow or action author.Patches
Users should upgrade to
@actions/core v1.9.1
.Workarounds
If you are unable to upgrade the
@actions/core
package, you can modify your action to ensure that any user input does not contain the delimiter_GitHubActionsFileCommandDelimeter_
before callingcore.exportVariable
.References
More information about setting-an-environment-variable in workflows
If you have any questions or comments about this advisory:
actions/toolkit
Release Notes
actions/toolkit (@actions/core)
### [`v1.9.1`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#191) - Randomize delimiter when calling `core.exportVariable` ### [`v1.9.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#190) - Added `toPosixPath`, `toWin32Path` and `toPlatformPath` utilities [#1102](https://togithub.com/actions/toolkit/pull/1102) ### [`v1.8.2`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#182) - Update to v2.0.1 of `@actions/http-client` [#1087](https://togithub.com/actions/toolkit/pull/1087) ### [`v1.8.1`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#181) - Update to v2.0.0 of `@actions/http-client` ### [`v1.8.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#180) - Deprecate `markdownSummary` extension export in favor of `summary` - [https://github.com/actions/toolkit/pull/1072](https://togithub.com/actions/toolkit/pull/1072) - [https://github.com/actions/toolkit/pull/1073](https://togithub.com/actions/toolkit/pull/1073) ### [`v1.7.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#170) - [Added `markdownSummary` extension](https://togithub.com/actions/toolkit/pull/1014) ### [`v1.6.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#160) - [Added OIDC Client function `getIDToken`](https://togithub.com/actions/toolkit/pull/919) - [Added `file` parameter to `AnnotationProperties`](https://togithub.com/actions/toolkit/pull/896) ### [`v1.5.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#150) - [Added support for notice annotations and more annotation fields](https://togithub.com/actions/toolkit/pull/855) ### [`v1.4.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#140) - [Added the `getMultilineInput` function](https://togithub.com/actions/toolkit/pull/829) ### [`v1.3.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#130) - [Added the trimWhitespace option to getInput](https://togithub.com/actions/toolkit/pull/802) - [Added the getBooleanInput function](https://togithub.com/actions/toolkit/pull/725) ### [`v1.2.7`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#127) - [Prepend newline for set-output](https://togithub.com/actions/toolkit/pull/772)Configuration
📅 Schedule: Branch creation - "" in timezone Europe/Moscow, Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.