Skip to content

fix: validate refs before CI bootstrap downloads - #188

Merged
fengmk2 merged 2 commits into
mainfrom
fix/validate-setup-ref
Oct 8, 2026
Merged

fengmk2 merged 2 commits into
mainfrom
fix/validate-setup-ref

Conversation

@fengmk2

@fengmk2 fengmk2 commented Oct 8, 2026

Copy link
Copy Markdown
Member

An unchecked setup-ref can redirect GitLab downloads to another GitHub repository and execute its code on the runner.

Both GitLab templates now check setup-ref before script interpolation and reject unsafe SETUP_VP_SETUP_REF values before bootstrap downloads. The GitLab and Azure bootstrap scripts also check refs before runtime downloads.

Accepted refs contain ASCII letters, digits, underscores, and hyphens, with single dots or slashes between groups.

@fengmk2
fengmk2 merged commit 38584ab into main Oct 8, 2026
83 checks passed
@fengmk2
fengmk2 deleted the fix/validate-setup-ref branch October 8, 2026 05:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant