Skip to content

Commit 711a99c

Browse files
committed
Pass the test JDK's path to the build as a variable
The JDK jobs in ci.yml put ${{ steps.test-jdk.outputs.path }}, the path actions/setup-java reports, straight into the build's shell script. zizmor (template-injection) flags that: a template expansion is pasted into the script before the shell runs it, so a value with shell syntax in it would run as code. The path now reaches the shell as TEST_JDK in the step's environment and is quoted there. The matrix values stay inline: they are fixed in the workflow itself, and zizmor does not flag them.
1 parent e89a83a commit 711a99c

1 file changed

Lines changed: 5 additions & 2 deletions

File tree

‎.github/workflows/ci.yml‎

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -89,11 +89,14 @@ jobs:
8989
REASON: ${{ matrix.gradle_args_reason }}
9090
run: echo "::notice title=JDK ${{ matrix.jdk }} runs with $GRADLE_ARGS::$REASON"
9191

92-
# Gradle does not look into the runner's tool cache, so it is told where the test JDK is.
92+
# Gradle does not look into the runner's tool cache, so it is told where the test JDK is. The path is
93+
# a step's output, so it reaches the shell as a variable rather than being pasted into the script.
9394
- name: Build
95+
env:
96+
TEST_JDK: ${{ steps.test-jdk.outputs.path }}
9497
run: >-
9598
./gradlew test -PjavaRuntime=${{ matrix.jdk }} ${{ matrix.gradle_args }}
96-
-Porg.gradle.java.installations.paths=${{ steps.test-jdk.outputs.path }}
99+
-Porg.gradle.java.installations.paths="$TEST_JDK"
97100
98101
- name: Publish Test Report
99102
uses: mikepenz/action-junit-report@a9170d5795813c01ab4901ffb045b52bab4ab09d # v6.5.0

0 commit comments

Comments
 (0)