Skip to content

Commit 47746ad

Browse files
committed
fix(ci): potential security vulnerabilities
1 parent c69b0e9 commit 47746ad

File tree

2 files changed

+12
-4
lines changed

2 files changed

+12
-4
lines changed

.github/workflows/ci.yml

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -184,9 +184,13 @@ jobs:
184184
- name: Pull docker image (master)
185185
run: docker pull ghcr.io/lowlighter/metrics:master
186186
- name: Tag docker image (release)
187-
run: docker tag ghcr.io/lowlighter/metrics:master ghcr.io/lowlighter/metrics:$(echo '${{ github.event.head_commit.message }}' | grep -Po 'v\d+[.]\d+')
187+
env:
188+
GITHUB_COMMIT_MESSAGE: ${{ github.event.head_commit.message }}
189+
run: docker tag ghcr.io/lowlighter/metrics:master ghcr.io/lowlighter/metrics:$(echo $GITHUB_COMMIT_MESSAGE | grep -Po 'v\d+[.]\d+')
188190
- name: Publish release to GitHub registry
189-
run: docker push ghcr.io/lowlighter/metrics:$(echo '${{ github.event.head_commit.message }}' | grep -Po 'v\d+[.]\d+')
191+
env:
192+
GITHUB_COMMIT_MESSAGE: ${{ github.event.head_commit.message }}
193+
run: docker push ghcr.io/lowlighter/metrics:$(echo $GITHUB_COMMIT_MESSAGE | grep -Po 'v\d+[.]\d+')
190194
- name: Tag docker image (latest)
191195
run: docker tag ghcr.io/lowlighter/metrics:master ghcr.io/lowlighter/metrics:latest
192196
- name: Publish latest to GitHub registry

.github/workflows/test.yml

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -43,9 +43,13 @@ jobs:
4343
mkdir -v -p /home/runner/.cache/dprint/cache
4444
npx dprint fmt --config .github/config/dprint.json
4545
- name: Build lowlighter/metrics:${{ github.head_ref || 'master' }}
46-
run: docker build -t lowlighter/metrics:$(echo ${{ github.head_ref || 'master' }} | sed 's/\//-/g') .
46+
env:
47+
GIT_REF: ${{ github.head_ref || 'master' }}
48+
run: docker build -t lowlighter/metrics:$(echo $GIT_REF | sed 's/[^a-z]/-/g') .
4749
- name: Run tests
48-
run: docker run --rm --entrypoint="" lowlighter/metrics:$(echo ${{ github.head_ref || 'master' }} | sed 's/\//-/g') npm run test-metrics
50+
env:
51+
GIT_REF: ${{ github.head_ref || 'master' }}
52+
run: docker run --rm --entrypoint="" lowlighter/metrics:$(echo $GIT_REF | sed 's/[^a-z]/-/g') npm run test-metrics
4953

5054
# Run CodeQL on branch
5155
analyze:

0 commit comments

Comments
 (0)