Commit 711a99c
committed
Pass the test JDK's path to the build as a variable
The JDK jobs in ci.yml put ${{ steps.test-jdk.outputs.path }}, the
path actions/setup-java reports, straight into the build's shell
script. zizmor (template-injection) flags that: a template expansion is
pasted into the script before the shell runs it, so a value with shell
syntax in it would run as code. The path now reaches the shell as
TEST_JDK in the step's environment and is quoted there. The matrix
values stay inline: they are fixed in the workflow itself, and zizmor
does not flag them.1 parent e89a83a commit 711a99c
1 file changed
Lines changed: 5 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
89 | 89 | | |
90 | 90 | | |
91 | 91 | | |
92 | | - | |
| 92 | + | |
| 93 | + | |
93 | 94 | | |
| 95 | + | |
| 96 | + | |
94 | 97 | | |
95 | 98 | | |
96 | | - | |
| 99 | + | |
97 | 100 | | |
98 | 101 | | |
99 | 102 | | |
| |||
0 commit comments