• BehindTheBarrier@programming.dev
    link
    fedilink
    English
    arrow-up
    8
    ·
    9 days ago

    I never considered branch names to be a vector, but in hindsight it makes total sense when put into a workflow like that. What possibly surprised me even more, was that branch names weren’t limited to basic characters or at least no special signs. I obviously see the case for all the extended characters outside the latin alphabet, such as Chinese characters, but I totally expected restrictions on special symbols like ", ', /, \, ;, etc.

    • Thinker@lemmy.world
      link
      fedilink
      arrow-up
      12
      ·
      8 days ago

      Ding ding ding! We have a winner!

      It’s a third-party GitHub Action that is passing the branch name directly to Bash. So to be clear, not GitHub’s fault.

  • Artyom@lemm.ee
    link
    fedilink
    arrow-up
    0
    ·
    8 days ago

    Presumably they picked the repo because it will auto-merge MRs if they pass testing even without human approvals. Glad they caught it and good work to everyone involved, but I’m gonna file this one under my “fuck around, find out” folder.