Skip to content

fix(ci): pass major-tag input through env instead of shell interpolation - #156

Draft
cvscarlos wants to merge 1 commit into
mainfrom
major-tag-env-input
Draft

cvscarlos wants to merge 1 commit into
mainfrom
major-tag-env-input

Conversation

@cvscarlos

@cvscarlos cvscarlos commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Hardens ci.update-major-version-tag.yaml by reading the resolved tag from the step's env: instead of expanding ${{ ... }} inside the run: script.

This follows GitHub's recommendation for inline scripts: https://docs.github.com/en/actions/reference/security/secure-use#use-an-intermediate-environment-variable

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved issues were identified.

Review effort: Lite
Findings: None

What changed in this PR

Hardens the CI workflow by passing the resolved major tag through an environment variable instead of shell interpolation.

Changes:

  • Adds TAG_NAME to the step environment.
  • Preserves existing validation and tag-update behavior.
File Description
.github/​workflows/​ci.update-major-version-tag.yaml Uses an environment variable for safer tag handling.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@cvscarlos
cvscarlos marked this pull request as ready for review October 2, 2026 15:31
@cvscarlos
cvscarlos requested a review from a team as a code owner October 2, 2026 15:31
@kpplis

kpplis commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

@cvscarlos did you test this by pointing your target workflow to this branch and running it? We need to confirm it's not braking things before merging.

@cvscarlos
cvscarlos marked this pull request as draft October 5, 2026 11:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants