-
Notifications
You must be signed in to change notification settings - Fork 23
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
build: Update dependency @actions/core to v1.9.1 [SECURITY] - autoclosed #143
Closed
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
renovate
bot
force-pushed
the
renovate/npm-@actions/core-vulnerability
branch
4 times, most recently
from
March 16, 2023 09:52
684a37b
to
ec8ca91
Compare
renovate
bot
changed the title
build: Update dependency @actions/core to 1.9.1 [SECURITY]
build: Update dependency @actions/core to v1.9.1 [SECURITY]
Mar 24, 2023
renovate
bot
force-pushed
the
renovate/npm-@actions/core-vulnerability
branch
from
April 11, 2023 02:51
ec8ca91
to
33b5f7c
Compare
renovate
bot
force-pushed
the
renovate/npm-@actions/core-vulnerability
branch
from
April 25, 2023 10:30
33b5f7c
to
10955d8
Compare
renovate
bot
changed the title
build: Update dependency @actions/core to v1.9.1 [SECURITY]
build: Update dependency @actions/core to 1.9.1 [SECURITY]
May 17, 2023
renovate
bot
changed the title
build: Update dependency @actions/core to 1.9.1 [SECURITY]
build: Update dependency @actions/core to v1.9.1 [SECURITY]
May 28, 2023
renovate
bot
force-pushed
the
renovate/npm-@actions/core-vulnerability
branch
7 times, most recently
from
July 12, 2023 07:49
022f4ed
to
86ba282
Compare
renovate
bot
force-pushed
the
renovate/npm-@actions/core-vulnerability
branch
4 times, most recently
from
August 9, 2023 13:13
5a90187
to
b4136cb
Compare
renovate
bot
force-pushed
the
renovate/npm-@actions/core-vulnerability
branch
3 times, most recently
from
August 22, 2023 00:39
06e2493
to
85d1160
Compare
renovate
bot
force-pushed
the
renovate/npm-@actions/core-vulnerability
branch
3 times, most recently
from
September 15, 2023 00:54
fefd6e4
to
49c4fe3
Compare
renovate
bot
force-pushed
the
renovate/npm-@actions/core-vulnerability
branch
2 times, most recently
from
October 15, 2023 09:37
4ce70a7
to
921ecb5
Compare
renovate
bot
force-pushed
the
renovate/npm-@actions/core-vulnerability
branch
from
October 23, 2023 09:49
921ecb5
to
190083f
Compare
renovate
bot
force-pushed
the
renovate/npm-@actions/core-vulnerability
branch
from
November 6, 2023 08:37
190083f
to
1163e05
Compare
renovate
bot
force-pushed
the
renovate/npm-@actions/core-vulnerability
branch
from
November 16, 2023 10:32
1163e05
to
4106735
Compare
renovate
bot
force-pushed
the
renovate/npm-@actions/core-vulnerability
branch
from
December 3, 2023 13:22
4106735
to
0144baf
Compare
renovate
bot
force-pushed
the
renovate/npm-@actions/core-vulnerability
branch
7 times, most recently
from
February 1, 2024 20:23
d2a266d
to
7b0d5b9
Compare
renovate
bot
force-pushed
the
renovate/npm-@actions/core-vulnerability
branch
from
February 25, 2024 10:14
7b0d5b9
to
ab8f500
Compare
renovate
bot
force-pushed
the
renovate/npm-@actions/core-vulnerability
branch
from
March 12, 2024 10:58
ab8f500
to
aeee55c
Compare
renovate
bot
force-pushed
the
renovate/npm-@actions/core-vulnerability
branch
2 times, most recently
from
April 6, 2024 03:25
b8e0d5c
to
3c7bcce
Compare
renovate
bot
force-pushed
the
renovate/npm-@actions/core-vulnerability
branch
2 times, most recently
from
May 9, 2024 12:36
66b912a
to
7636239
Compare
renovate
bot
force-pushed
the
renovate/npm-@actions/core-vulnerability
branch
from
June 4, 2024 11:46
7636239
to
9811cd8
Compare
renovate
bot
changed the title
build: Update dependency @actions/core to v1.9.1 [SECURITY]
build: Update dependency @actions/core to v1.9.1 [SECURITY] - autoclosed
Aug 6, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.2.6
->1.9.1
GitHub Vulnerability Alerts
CVE-2022-35954
Impact
The
core.exportVariable
function uses a well known delimiter that attackers can use to break out of that specific variable and assign values to other arbitrary variables. Workflows that write untrusted values to theGITHUB_ENV
file may cause the path or other environment variables to be modified without the intention of the workflow or action author.Patches
Users should upgrade to
@actions/core v1.9.1
.Workarounds
If you are unable to upgrade the
@actions/core
package, you can modify your action to ensure that any user input does not contain the delimiter_GitHubActionsFileCommandDelimeter_
before callingcore.exportVariable
.References
More information about setting-an-environment-variable in workflows
If you have any questions or comments about this advisory:
actions/toolkit
Release Notes
actions/toolkit (@actions/core)
v1.9.1
core.exportVariable
v1.9.0
toPosixPath
,toWin32Path
andtoPlatformPath
utilities #1102v1.8.2
@actions/http-client
#1087v1.8.1
@actions/http-client
v1.8.0
markdownSummary
extension export in favor ofsummary
v1.7.0
markdownSummary
extensionv1.6.0
getIDToken
file
parameter toAnnotationProperties
v1.5.0
v1.4.0
getMultilineInput
functionv1.3.0
v1.2.7
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.