sonatype-nexus-community / codetocloud-workshop

Other
1 stars 8 forks source link

Unsanitized inputs on Github workflows #32

Open mperezrodiguez opened 1 year ago

mperezrodiguez commented 1 year ago

On https://github.com/sonatype-nexus-community/codetocloud-workshop/blob/main/.github/workflows/build.yml (and other workflows).

Unsanitized strings could lead to arbitrary code execution on malicious definitions and/or configurations.