Compare commits

...

4 Commits

Author SHA1 Message Date
Gabriele Bartolini
020fa3f8fe
Merge 7135dd43a6 into ce7b7612ae 2026-03-06 10:47:39 +01:00
Marco Nenciarini
ce7b7612ae
fix(security): harden GitHub Actions workflows against expression injection (#773)
Some checks failed
release-please / release-please (push) Failing after 3s
Move `${{ }}` expressions from `run:` blocks into step-level `env:`
blocks, then reference them as properly-quoted shell variables.

Part of cloudnative-pg/cloudnative-pg#10113

Assisted-by: Claude Opus 4.6

Signed-off-by: Marco Nenciarini <marco.nenciarini@enterprisedb.com>
2026-03-06 10:37:54 +01:00
Gabriele Bartolini
7135dd43a6 chore: use docker versioning
Signed-off-by: Gabriele Bartolini <gabriele.bartolini@enterprisedb.com>
2026-03-06 12:40:57 +11:00
Gabriele Bartolini
96c360ff4d chore: update registry version to 3.0.0 in Taskfile
Closes #777

Signed-off-by: Gabriele Bartolini <gabriele.bartolini@enterprisedb.com>
2026-03-06 12:09:51 +11:00
2 changed files with 6 additions and 4 deletions

View File

@ -51,10 +51,12 @@ jobs:
# We use a GitHub token with write permissions to create the release,
# otherwise we won't be able to trigger a new run when pushing on main.
- name: Run release-please
env:
REPO_URL: ${{ github.repository }}
run: |
npx release-please release-pr \
--token="${{ secrets.REPO_PAT }}" \
--repo-url="${{ github.repository }}"
--repo-url="${REPO_URL}"
npx release-please github-release \
--token="${{ secrets.REPO_PAT }}" \
--repo-url="${{ github.repository }}"
--repo-url="${REPO_URL}"

View File

@ -183,8 +183,8 @@ tasks:
- generate-certs
- start-build-network
env:
# TODO: renovate
REGISTRY_VERSION: 2
# renovate: datasource=docker depName=registry versioning=semver
REGISTRY_VERSION: 3
cmds:
- >
docker run -d --name {{ .REGISTRY_NAME }}