Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

build: Update dependency @actions/core to v1.9.1 [SECURITY] - autoclosed #143

Closed
wants to merge 1 commit into from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Aug 18, 2022

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
@actions/core (source) 1.2.6 -> 1.9.1 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2022-35954

Impact

The core.exportVariable function uses a well known delimiter that attackers can use to break out of that specific variable and assign values to other arbitrary variables. Workflows that write untrusted values to the GITHUB_ENV file may cause the path or other environment variables to be modified without the intention of the workflow or action author.

Patches

Users should upgrade to @actions/core v1.9.1.

Workarounds

If you are unable to upgrade the @actions/core package, you can modify your action to ensure that any user input does not contain the delimiter _GitHubActionsFileCommandDelimeter_ before calling core.exportVariable.

References

More information about setting-an-environment-variable in workflows

If you have any questions or comments about this advisory:


Release Notes

actions/toolkit (@​actions/core)

v1.9.1

  • Randomize delimiter when calling core.exportVariable

v1.9.0

  • Added toPosixPath, toWin32Path and toPlatformPath utilities #​1102

v1.8.2

  • Update to v2.0.1 of @actions/http-client #​1087

v1.8.1

  • Update to v2.0.0 of @actions/http-client

v1.8.0

v1.7.0

v1.6.0

v1.5.0

v1.4.0

v1.3.0

v1.2.7


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/npm-@actions/core-vulnerability branch 4 times, most recently from 684a37b to ec8ca91 Compare March 16, 2023 09:52
@renovate renovate bot changed the title build: Update dependency @actions/core to 1.9.1 [SECURITY] build: Update dependency @actions/core to v1.9.1 [SECURITY] Mar 24, 2023
@renovate renovate bot force-pushed the renovate/npm-@actions/core-vulnerability branch from ec8ca91 to 33b5f7c Compare April 11, 2023 02:51
@renovate renovate bot force-pushed the renovate/npm-@actions/core-vulnerability branch from 33b5f7c to 10955d8 Compare April 25, 2023 10:30
@renovate renovate bot changed the title build: Update dependency @actions/core to v1.9.1 [SECURITY] build: Update dependency @actions/core to 1.9.1 [SECURITY] May 17, 2023
@renovate renovate bot changed the title build: Update dependency @actions/core to 1.9.1 [SECURITY] build: Update dependency @actions/core to v1.9.1 [SECURITY] May 28, 2023
@renovate renovate bot force-pushed the renovate/npm-@actions/core-vulnerability branch 7 times, most recently from 022f4ed to 86ba282 Compare July 12, 2023 07:49
@renovate renovate bot force-pushed the renovate/npm-@actions/core-vulnerability branch 4 times, most recently from 5a90187 to b4136cb Compare August 9, 2023 13:13
@renovate renovate bot force-pushed the renovate/npm-@actions/core-vulnerability branch 3 times, most recently from 06e2493 to 85d1160 Compare August 22, 2023 00:39
@renovate renovate bot force-pushed the renovate/npm-@actions/core-vulnerability branch 3 times, most recently from fefd6e4 to 49c4fe3 Compare September 15, 2023 00:54
@renovate renovate bot force-pushed the renovate/npm-@actions/core-vulnerability branch 2 times, most recently from 4ce70a7 to 921ecb5 Compare October 15, 2023 09:37
@renovate renovate bot force-pushed the renovate/npm-@actions/core-vulnerability branch from 921ecb5 to 190083f Compare October 23, 2023 09:49
@renovate renovate bot force-pushed the renovate/npm-@actions/core-vulnerability branch from 190083f to 1163e05 Compare November 6, 2023 08:37
@renovate renovate bot force-pushed the renovate/npm-@actions/core-vulnerability branch from 1163e05 to 4106735 Compare November 16, 2023 10:32
@renovate renovate bot force-pushed the renovate/npm-@actions/core-vulnerability branch from 4106735 to 0144baf Compare December 3, 2023 13:22
@renovate renovate bot force-pushed the renovate/npm-@actions/core-vulnerability branch 7 times, most recently from d2a266d to 7b0d5b9 Compare February 1, 2024 20:23
@renovate renovate bot force-pushed the renovate/npm-@actions/core-vulnerability branch from 7b0d5b9 to ab8f500 Compare February 25, 2024 10:14
@renovate renovate bot force-pushed the renovate/npm-@actions/core-vulnerability branch from ab8f500 to aeee55c Compare March 12, 2024 10:58
@renovate renovate bot force-pushed the renovate/npm-@actions/core-vulnerability branch 2 times, most recently from b8e0d5c to 3c7bcce Compare April 6, 2024 03:25
@renovate renovate bot force-pushed the renovate/npm-@actions/core-vulnerability branch 2 times, most recently from 66b912a to 7636239 Compare May 9, 2024 12:36
@renovate renovate bot force-pushed the renovate/npm-@actions/core-vulnerability branch from 7636239 to 9811cd8 Compare June 4, 2024 11:46
@renovate renovate bot changed the title build: Update dependency @actions/core to v1.9.1 [SECURITY] build: Update dependency @actions/core to v1.9.1 [SECURITY] - autoclosed Aug 6, 2024
@renovate renovate bot closed this Aug 6, 2024
@renovate renovate bot deleted the renovate/npm-@actions/core-vulnerability branch August 6, 2024 08:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants