Skip to content

fix: pin 4 unpinned action(s),extract 303 unsafe expression(s) to env…#450

Open
sundb wants to merge 4 commits into
unstablefrom
fix-ci-security-test
Open

fix: pin 4 unpinned action(s),extract 303 unsafe expression(s) to env…#450
sundb wants to merge 4 commits into
unstablefrom
fix-ci-security-test

Conversation

@sundb

@sundb sundb commented Apr 8, 2026

Copy link
Copy Markdown
Owner

… vars… vars

dagecko added 4 commits March 26, 2026 18:27
Cleaning up quoting on extracted env var references for consistency
and correctness.

Note: daily.yml test args (INPUT_TEST_ARGS, INPUT_CLUSTER_TEST_ARGS)
are intentionally left unquoted as they contain multiple space-separated
flags that need word splitting to work correctly.
Remove workflow_dispatch input extractions from daily.yml per
maintainer feedback — those inputs are maintainer-only and do not
need intermediate env vars.

Keep:
- codecov/codecov-action SHA pin (supply chain hardening)
- COVERITY_SCAN_TOKEN / COVERITY_SCAN_EMAIL moved to env blocks
Per reviewer request, updated the SHA pin to codecov/codecov-action v6.
Only breaking change is Node.js 24 requirement, no config changes needed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants