Fix template injection in e2e-versions.yml (zizmor alert #122) - #1120
Merged
Conversation
Copilot
AI
changed the title
[WIP] Fix code scanning alert #122
Fix template injection in e2e-versions.yml (zizmor alert #122)
Jul 14, 2026
brunoborges
marked this pull request as ready for review
July 14, 2026 19:55
Copilot stopped reviewing on behalf of
brunoborges due to an error
July 14, 2026 19:55
Contributor
There was a problem hiding this comment.
Pull request overview
Note
Copilot was unable to run its full agentic suite in this review.
Updates the e2e GitHub Actions workflow to verify Java 21 setup outputs using step-scoped environment variables, improving shell interpolation consistency.
Changes:
- Pass
setup-java-21outputs into the verification step viaenv - Update verification script to reference
$JAVA_21_PATH/$JAVA_21_VERSIONinstead of inline${{ ... }}expressions
Show a summary per file
| File | Description |
|---|---|
| .github/workflows/e2e-versions.yml | Refactors the Java 21 output verification step to use environment variables for easier/safer shell usage |
Review details
Tip
Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
- Files reviewed: 1/1 changed files
- Comments generated: 0
- Review effort level: Low
3 tasks
mergify Bot
added a commit
to ArcadeData/arcadedb
that referenced
this pull request
Aug 30, 2026
Bumps [actions/setup-java](https://github.com/actions/setup-java) from 5.7.0 to 6.0.0. Release notes *Sourced from [actions/setup-java's releases](https://github.com/actions/setup-java/releases).* > v6.0.0 > ------ > > What's Changed > -------------- > > * dist: Migrate from Zulu Discovery API to Azul Metadata API by [`@jameswald`](https://github.com/jameswald) in [actions/setup-java#1010](https://redirect.github.com/actions/setup-java/pull/1010) > * feat: add .mvn/extensions.xml to Maven cache key pattern by [`@brunoborges`](https://github.com/brunoborges) with [`@Copilot`](https://github.com/Copilot) in [actions/setup-java#1041](https://redirect.github.com/actions/setup-java/pull/1041) > * Migrate to ESM and upgrade dependencies by [`@priyagupta108`](https://github.com/priyagupta108) in [actions/setup-java#1078](https://redirect.github.com/actions/setup-java/pull/1078) > * Map Zulu x86 architecture to i686 for Azul Metadata API by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1079](https://redirect.github.com/actions/setup-java/pull/1079) > * Rename jdkFile input to jdk-file with deprecated alias by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1083](https://redirect.github.com/actions/setup-java/pull/1083) > * Infer distribution from asdf .tool-versions vendor prefix by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1084](https://redirect.github.com/actions/setup-java/pull/1084) > * Add Maven compiler problem matcher for javac diagnostics by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1086](https://redirect.github.com/actions/setup-java/pull/1086) > * feat: expose cache-primary-key output ([#597](https://redirect.github.com/actions/setup-java/issues/597)) by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1088](https://redirect.github.com/actions/setup-java/pull/1088) > * docs: clarify V6 ESM migration is not a user-facing breaking change by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1090](https://redirect.github.com/actions/setup-java/pull/1090) > * Support multi-field Java versions like `18.0.1.1` by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1092](https://redirect.github.com/actions/setup-java/pull/1092) > * docs: document seeding the Maven cache for plugin dependencies by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1094](https://redirect.github.com/actions/setup-java/pull/1094) > * docs: clarify Maven cache paths and key hash inputs by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1096](https://redirect.github.com/actions/setup-java/pull/1096) > * Support pinning java-version as "latest" by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1093](https://redirect.github.com/actions/setup-java/pull/1093) > * chore(deps-dev): bump eslint from 10.6.0 to 10.7.0 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/setup-java#1101](https://redirect.github.com/actions/setup-java/pull/1101) > * chore(deps-dev): bump eslint-plugin-n from 18.2.1 to 18.2.2 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/setup-java#1103](https://redirect.github.com/actions/setup-java/pull/1103) > * chore(deps-dev): bump prettier from 3.9.4 to 3.9.5 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/setup-java#1105](https://redirect.github.com/actions/setup-java/pull/1105) > * chore(deps): bump actions/checkout from 6 to 7 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/setup-java#1106](https://redirect.github.com/actions/setup-java/pull/1106) > * chore(deps-dev): bump `@types/node` from 26.1.0 to 26.1.1 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/setup-java#1104](https://redirect.github.com/actions/setup-java/pull/1104) > * dist: Cover Tencent Kona JDK 25 by [`@johnshajiang`](https://github.com/johnshajiang) in [actions/setup-java#1108](https://redirect.github.com/actions/setup-java/pull/1108) > * chore(deps-dev): bump typescript from 6.0.3 to 7.0.2 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/setup-java#1102](https://redirect.github.com/actions/setup-java/pull/1102) > * Preserve Maven toolchains across repeated setup-java runs ([#1099](https://redirect.github.com/actions/setup-java/issues/1099)) by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1111](https://redirect.github.com/actions/setup-java/pull/1111) > * dist: Support Liberica NIK ([#878](https://redirect.github.com/actions/setup-java/issues/878)) by [`@asm0dey`](https://github.com/asm0dey) in [actions/setup-java#1112](https://redirect.github.com/actions/setup-java/pull/1112) > * Fix template injection (zizmor alert [#118](https://redirect.github.com/actions/setup-java/issues/118)) in e2e-versions.yml by [`@brunoborges`](https://github.com/brunoborges) with [`@Copilot`](https://github.com/Copilot) in [actions/setup-java#1114](https://redirect.github.com/actions/setup-java/pull/1114) > * Fix template injection in e2e-versions.yml (zizmor alert [#122](https://redirect.github.com/actions/setup-java/issues/122)) by [`@brunoborges`](https://github.com/brunoborges) with [`@Copilot`](https://github.com/Copilot) in [actions/setup-java#1120](https://redirect.github.com/actions/setup-java/pull/1120) > * Disable persisted checkout credentials in e2e workflow by [`@brunoborges`](https://github.com/brunoborges) with [`@Copilot`](https://github.com/Copilot) in [actions/setup-java#1115](https://redirect.github.com/actions/setup-java/pull/1115) > * feat: Update recommended configuration for GPG signing by [`@wetneb`](https://github.com/wetneb) in [actions/setup-java#608](https://redirect.github.com/actions/setup-java/pull/608) > * Cache Maven and Gradle wrapper distributions separately from the dependency cache by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1097](https://redirect.github.com/actions/setup-java/pull/1097) > * Consolidate cache-dependency-path e2e workflow and add maven/sbt coverage by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1124](https://redirect.github.com/actions/setup-java/pull/1124) > * Use gpg.passphraseEnvName instead of the deprecated gpg.passphrase server by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1123](https://redirect.github.com/actions/setup-java/pull/1123) > * Extract repeated directory-check assertions into check-dir.sh helper by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1127](https://redirect.github.com/actions/setup-java/pull/1127) > * Consolidate duplicate jobs in e2e-versions workflow by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1125](https://redirect.github.com/actions/setup-java/pull/1125) > * Use YAML anchors to reduce boilerplate in e2e-versions workflow by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1126](https://redirect.github.com/actions/setup-java/pull/1126) > * Updated msft json for now by [`@jmjaffe37`](https://github.com/jmjaffe37) in [actions/setup-java#1129](https://redirect.github.com/actions/setup-java/pull/1129) > * Document missing action inputs in README by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1130](https://redirect.github.com/actions/setup-java/pull/1130) > * chore(deps): bump `@actions/cache` to 6.2.0 by [`@philip-gai`](https://github.com/philip-gai) in [actions/setup-java#1128](https://redirect.github.com/actions/setup-java/pull/1128) > * Add an option to disable Java problem matchers by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1133](https://redirect.github.com/actions/setup-java/pull/1133) > * docs: update setup-java examples by [`@HarithaVattikuti`](https://github.com/HarithaVattikuti) in [actions/setup-java#1131](https://redirect.github.com/actions/setup-java/pull/1131) > * Clarify credential environment variable inputs by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1134](https://redirect.github.com/actions/setup-java/pull/1134) > * chore(deps-dev): bump `@typescript-eslint/eslint-plugin` from 8.63.0 to 8.64.0 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/setup-java#1135](https://redirect.github.com/actions/setup-java/pull/1135) > * chore(deps): bump actions/setup-python from 6 to 7 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/setup-java#1143](https://redirect.github.com/actions/setup-java/pull/1143) > * chore(deps): bump fast-xml-parser from 5.9.3 to 5.10.1 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/setup-java#1142](https://redirect.github.com/actions/setup-java/pull/1142) > * chore(deps-dev): bump `@typescript-eslint/parser` from 8.64.0 to 8.65.0 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/setup-java#1138](https://redirect.github.com/actions/setup-java/pull/1138) > * chore(deps-dev): bump lint-staged from 17.0.8 to 17.2.0 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/setup-java#1136](https://redirect.github.com/actions/setup-java/pull/1136) > * chore(deps-dev): bump typescript from 6.0.3 to 7.0.2 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/setup-java#1137](https://redirect.github.com/actions/setup-java/pull/1137) > * chore(deps): fix npm audited vulnerabilities by [`@mhoffrog`](https://github.com/mhoffrog) in [actions/setup-java#1140](https://redirect.github.com/actions/setup-java/pull/1140) > * Fix formatting issues in README.md by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1144](https://redirect.github.com/actions/setup-java/pull/1144) > * Remediate npm audit findings and rebuild distributions by [`@brunoborges`](https://github.com/brunoborges) with [`@Copilot`](https://github.com/Copilot) in [actions/setup-java#1145](https://redirect.github.com/actions/setup-java/pull/1145) > * Set GRAALVM\_HOME for GraalVM distributions by [`@brunoborges`](https://github.com/brunoborges) with [`@Copilot`](https://github.com/Copilot) in [actions/setup-java#1146](https://redirect.github.com/actions/setup-java/pull/1146) ... (truncated) Commits * [`dd06d9c`](actions/setup-java@dd06d9c) Prepare documentation for v6 release ([#1253](https://redirect.github.com/actions/setup-java/issues/1253)) * [`59b3450`](actions/setup-java@59b3450) chore(deps): combine open Dependabot npm updates ([#1252](https://redirect.github.com/actions/setup-java/issues/1252)) * [`b96213d`](actions/setup-java@b96213d) Set default signature verification for supported distributions ([#1246](https://redirect.github.com/actions/setup-java/issues/1246)) * [`1dbac3c`](actions/setup-java@1dbac3c) docs: expose contributing guide to GitHub ([#1245](https://redirect.github.com/actions/setup-java/issues/1245)) * [`11741d6`](actions/setup-java@11741d6) ci: constrain cache e2e job modes ([#1244](https://redirect.github.com/actions/setup-java/issues/1244)) * [`ff99aa1`](actions/setup-java@ff99aa1) Fix Oracle macOS E2E version ([#1243](https://redirect.github.com/actions/setup-java/issues/1243)) * [`416c6d1`](actions/setup-java@416c6d1) Add Red Hat Build of OpenJDK support ([#1241](https://redirect.github.com/actions/setup-java/issues/1241)) * [`5f75b27`](actions/setup-java@5f75b27) Add Maven dependency-resolution repositories ([#1240](https://redirect.github.com/actions/setup-java/issues/1240)) * [`a42a52c`](actions/setup-java@a42a52c) Add multiple Maven server credentials ([#1239](https://redirect.github.com/actions/setup-java/issues/1239)) * [`fb4abd7`](actions/setup-java@fb4abd7) test: cover JDK 26 from SDKMAN ([#1238](https://redirect.github.com/actions/setup-java/issues/1238)) * Additional commits viewable in [compare view](actions/setup-java@b6effb0...dd06d9c) [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Resolves a
zizmor/template-injectioncode scanning alert by removing direct GitHub expression expansion inside arun:bash script, which could allow shell injection if output values contain metacharacters.Changes:
${{ steps.setup-java-21.outputs.path }}and${{ steps.setup-java-21.outputs.version }}from inline script expansion intoenv:variables (JAVA_21_PATH,JAVA_21_VERSION), consistent with the safe pattern used throughout the rest of the workflow.Related issue:
N/A — code scanning alert #122
Check list:
npm run checklocally (format, lint, build, test) and all checks pass.