Skip to content

SEC: fix exploitable template-injection surface (1/n)#369

Merged
Cadair merged 1 commit intoOpenAstronomy:mainfrom
neutrinoceros:sec/no-template-injection-1
Mar 9, 2026
Merged

SEC: fix exploitable template-injection surface (1/n)#369
Cadair merged 1 commit intoOpenAstronomy:mainfrom
neutrinoceros:sec/no-template-injection-1

Conversation

@neutrinoceros
Copy link
Contributor

extracted from #368
ref #364

@neutrinoceros neutrinoceros marked this pull request as ready for review March 9, 2026 12:04
@Cadair
Copy link
Member

Cadair commented Mar 9, 2026

Can you explain this one to me? Also do you want me to merge these two or wait for you to sort out the big one?

@neutrinoceros
Copy link
Contributor Author

Probably the best explanation is in zizmor's doc for the audit addressed here:
https://docs.zizmor.sh/audits/#template-injection

Also do you want me to merge these two or wait for you to sort out the big one?

I'm very disciplined about draft mode: if it's not a draft and CI is green, you can merge away without asking :)

@Cadair Cadair merged commit 12673ce into OpenAstronomy:main Mar 9, 2026
30 checks passed
@neutrinoceros neutrinoceros deleted the sec/no-template-injection-1 branch March 9, 2026 13:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants