Skip to content

ci: harden workflow inputs before shell use - #2225

Open
SashaMIT wants to merge 1 commit into
smartcontractkit:mainfrom
SashaMIT:ci-harden-build-cl-inputs
Open

SashaMIT wants to merge 1 commit into
smartcontractkit:mainfrom
SashaMIT:ci-harden-build-cl-inputs

Conversation

@SashaMIT

@SashaMIT SashaMIT commented Aug 5, 2026 •

Copy link
Copy Markdown

Summary

  • CI hygiene for .github/actions/build-cl and test_smoke.yml.
  • Bind free-string inputs (ton_ref, solana_ref, ccip_ref) under env: before run: script use (quoted $TON_REF / $SOLANA_REF / $CCIP_REF).
  • with: / ref: expressions left as-is (not shell script text).
  • Defense-in-depth for Actions composites — not framed as a vulnerability ticket.

Test plan

  • Workflow YAML review
  • Existing callers of build-cl / test_smoke with optional ton_ref / solana_ref / ccip_ref still resolve the same module versions

GitHub Actions expands ${{ }} before the shell runs. Binding ton_ref /
solana_ref / ccip_ref through env keeps those values out of the script
text (defense-in-depth for composite + smoke workflow inputs).
@SashaMIT
SashaMIT requested review from a team as code owners August 5, 2026 10:38

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant