Skip to content

Fix RCE vulnerability in workflow using environment variables#1355

Merged
5an7y-Microsoft merged 3 commits intomicrosoft:mainfrom
5an7y-Microsoft:main
Mar 13, 2026
Merged

Fix RCE vulnerability in workflow using environment variables#1355
5an7y-Microsoft merged 3 commits intomicrosoft:mainfrom
5an7y-Microsoft:main

Conversation

@5an7y-Microsoft
Copy link
Contributor

@5an7y-Microsoft 5an7y-Microsoft commented Mar 13, 2026

Fix RCE vulnerability in workflow using environment variables.

Tested:
image

Copilot AI and others added 3 commits March 13, 2026 18:06
… direct interpolation

Co-authored-by: 5an7y-Microsoft <219205893+5an7y-Microsoft@users.noreply.github.com>
…ity-in-workflow

Fix RCE in tag-codeowner-on-issue workflow via environment variables
@5an7y-Microsoft 5an7y-Microsoft marked this pull request as ready for review March 13, 2026 18:32
@5an7y-Microsoft 5an7y-Microsoft requested a review from a team as a code owner March 13, 2026 18:32
@5an7y-Microsoft 5an7y-Microsoft merged commit 925b258 into microsoft:main Mar 13, 2026
7 of 8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants