Skip to content

Prevent command injection when creating release notes#1419

Merged
Yang-33 merged 3 commits intomasterfrom
prevend-injection
Oct 15, 2025
Merged

Prevent command injection when creating release notes#1419
Yang-33 merged 3 commits intomasterfrom
prevend-injection

Conversation

@Yang-33
Copy link
Contributor

@Yang-33 Yang-33 commented Oct 14, 2025

If a merged PR title contains invalid strings, it could allow for shell injection. It's best to address known problems promptly.

@Yang-33 Yang-33 requested a review from a team October 14, 2025 08:06
@Yang-33 Yang-33 removed the request for review from a team October 14, 2025 08:15
- '20.12.2'
- '22'
- '24'
- '24.9.0'
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The latest Node version is not stable, so we've pinned the version.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@Yang-33 Yang-33 requested a review from a team October 14, 2025 08:22
@Yang-33 Yang-33 added this pull request to the merge queue Oct 15, 2025
Merged via the queue into master with commit 7ef4f08 Oct 15, 2025
12 checks passed
@Yang-33 Yang-33 deleted the prevend-injection branch October 15, 2025 00:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants