Commit Graph
2 Commits
Author SHA1 Message Date
sudacode 615a785703 test(release): assert workflow injection safety against parsed YAML
The line-based guards allow-listed known-safe spellings, so bracket forms
like ${{ steps.version.outputs['VERSION'] }} never entered the candidate
list and passed, and the ordering check read indexOf over raw text, which
a comment naming the step could satisfy.

Parse the workflows instead and assert on step structure: no template
expression may appear in any run body, every step reading $RELEASE_VERSION
or $TAG_NAME must declare it in env, and the prerelease notes check must
precede the publishing step in the release job's step list.

Verified each guard fails on the three evasions it now covers.
2026-08-23 03:45:29 -07:00
sudacode 7b403bf8ad test(release): cover workflow injection safety and prerelease note check
The AUR test pinned the literal ${{ steps.version.outputs.VERSION }}
interpolation that moved into an env block, so it failed once the tag
value started reaching the shell as $RELEASE_VERSION.

Update that assertion and add guards for the invariant behind the move:
no tag-derived value may be interpolated into a run body, where GitHub
substitutes it before the shell parses the line. Also assert the
prerelease workflow runs the committed-notes check before it creates or
edits the release.

Document that the fragment delta resolves git paths against cwd, which
is both the project root and the repository root.
2026-08-23 03:17:06 -07:00