AlexRogalskiy / github-action-quotes

📜 GitHub action to generate styled quotes
https://github.com/marketplace/actions/styled-quotes
GNU General Public License v3.0
2 stars 1 forks source link

:arrow_up: Updates @actions/core to v1.9.1 [SECURITY] #571

Open renovate[bot] opened 1 year ago

renovate[bot] commented 1 year ago

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
@actions/core (source) 1.2.6 -> 1.9.1 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2022-35954

Impact

The core.exportVariable function uses a well known delimiter that attackers can use to break out of that specific variable and assign values to other arbitrary variables. Workflows that write untrusted values to the GITHUB_ENV file may cause the path or other environment variables to be modified without the intention of the workflow or action author.

Patches

Users should upgrade to @actions/core v1.9.1.

Workarounds

If you are unable to upgrade the @actions/core package, you can modify your action to ensure that any user input does not contain the delimiter _GitHubActionsFileCommandDelimeter_ before calling core.exportVariable.

References

More information about setting-an-environment-variable in workflows

If you have any questions or comments about this advisory:


Release Notes

actions/toolkit (@​actions/core) ### [`v1.9.1`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#191) - Randomize delimiter when calling `core.exportVariable` ### [`v1.9.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#190) - Added `toPosixPath`, `toWin32Path` and `toPlatformPath` utilities [#​1102](https://togithub.com/actions/toolkit/pull/1102) ### [`v1.8.2`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#182) - Update to v2.0.1 of `@actions/http-client` [#​1087](https://togithub.com/actions/toolkit/pull/1087) ### [`v1.8.1`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#181) - Update to v2.0.0 of `@actions/http-client` ### [`v1.8.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#180) - Deprecate `markdownSummary` extension export in favor of `summary` - [https://github.com/actions/toolkit/pull/1072](https://togithub.com/actions/toolkit/pull/1072) - [https://github.com/actions/toolkit/pull/1073](https://togithub.com/actions/toolkit/pull/1073) ### [`v1.7.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#170) - [Added `markdownSummary` extension](https://togithub.com/actions/toolkit/pull/1014) ### [`v1.6.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#160) - [Added OIDC Client function `getIDToken`](https://togithub.com/actions/toolkit/pull/919) - [Added `file` parameter to `AnnotationProperties`](https://togithub.com/actions/toolkit/pull/896) ### [`v1.5.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#150) - [Added support for notice annotations and more annotation fields](https://togithub.com/actions/toolkit/pull/855) ### [`v1.4.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#140) - [Added the `getMultilineInput` function](https://togithub.com/actions/toolkit/pull/829) ### [`v1.3.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#130) - [Added the trimWhitespace option to getInput](https://togithub.com/actions/toolkit/pull/802) - [Added the getBooleanInput function](https://togithub.com/actions/toolkit/pull/725) ### [`v1.2.7`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#127) - [Prepend newline for set-output](https://togithub.com/actions/toolkit/pull/772)

Configuration

📅 Schedule: Branch creation - "" in timezone Europe/Moscow, Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.



This PR has been generated by Mend Renovate. View repository job log here.

renovate[bot] commented 1 year ago

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.


changelogg[bot] commented 1 year ago

Hey! Changelogs info seems to be missing or might be in incorrect format. Please use the below template in PR description to ensure Changelogg can detect your changes:

    - (tag) changelog_text
or
```
- tag: changelog_text
```
**OR**
You can add tag in PR header or while doing a commit too
```    
(tag) PR header
```
or
```
tag: PR header
```
Valid tags: **added** / **feat**, **changed**, **deprecated**, **fixed** / **fix**, **removed**, **security**, **build**, **ci**, **chore**, **docs**, **perf**, **refactor**, **revert**, **style**, **test**
Thanks!
For more info, check out [changelogg docs](https://docs.changelogg.io/)
viezly[bot] commented 1 year ago

Pull request by bot. No need to analyze

github-actions[bot] commented 1 year ago

Thanks for the PR!

This section of the codebase is owner by https://github.com/AlexRogalskiy/ - if they write a comment saying "LGTM" then it will be merged.

github-actions[bot] commented 1 year ago

🏷️ [bumpr] Next version:v2.19.1 Changes:v2.19.0...AlexRogalskiy:renovate/npm-@actions/core-vulnerability

socket-security[bot] commented 6 months ago

Updated dependencies detected. Learn more about Socket for GitHub ↗︎

Packages Version New capabilities Transitives Size Publisher
@actions/core 1.2.6...1.10.1 network, filesystem, environment +4/-0 1.46 MB thboop