Files
alls-green/action.yml
Alberto Garcia Illera 98fac3d0c4 Fix script injection risk by passing inputs via env vars
Move action input interpolation from the shell script body into the
env block. This prevents potential script injection via crafted input
values, since environment variables are assigned before the shell
interprets the script — values can never break out of their string
context.

This also eliminates the heredoc complexity, improving readability.
2026-02-06 10:44:06 -08:00

62 lines
1.7 KiB
YAML

---
name: alls-green
description: >-
GitHub Action for checking that the test matrix jobs are all
successful before proceeding. To be used in branch protection
author: >-
Sviatoslav Sydorenko <wk+~github.com/re-actors/[email protected]>
branding:
icon: check-circle
color: green
inputs:
jobs:
description: >-
A list of jobs from the `needs` context, serialized as a JSON
string via `toJSON(needs)`
required: true
allowed-failures:
default: >-
[]
description: >-
Job names that are allowed to fail and not affect the outcome,
as a comma-separated list or serialized as a JSON string
required: false
allowed-skips:
default: >-
[]
description: >-
Job names that are allowed to be skipped and not affect the
outcome, as a comma-separated list or serialized as a JSON string
required: false
outputs:
failure:
description: Whether this check decided that the job matrix failed.
value: ${{ steps.outcome.outputs.failure }}
result:
description: Failure or success result of the job matrix.
value: ${{ steps.outcome.outputs.result }}
success:
description: Whether this check decided that the job matrix succeeded.
value: ${{ steps.outcome.outputs.success }}
runs:
using: composite
steps:
- name: Decide whether the input jobs succeeded or failed
id: outcome
env:
INPUT_ALLOWED_FAILURES: ${{ inputs.allowed-failures }}
INPUT_ALLOWED_SKIPS: ${{ inputs.allowed-skips }}
INPUT_JOBS: ${{ inputs.jobs }}
PYTHONPATH: ${{ github.action_path }}/src
run: |
python -m normalize_needed_jobs_status \
"$INPUT_ALLOWED_FAILURES" \
"$INPUT_ALLOWED_SKIPS" \
"$INPUT_JOBS"
shell: bash
...