Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 12 additions & 6 deletions .github/workflows/deploy-hf-env.yml
Original file line number Diff line number Diff line change
Expand Up @@ -67,27 +67,33 @@ jobs:
env:
HF_TOKEN: ${{ secrets.HF_TOKEN }}
ENVS_CSV_INPUT: ${{ github.event.inputs.envs_csv }}
GITHUB_EVENT_INPUTS_HF_NAMESPACE: ${{ github.event.inputs.hf_namespace }}
GITHUB_EVENT_INPUTS_OPENENV_VERSION: ${{ github.event.inputs.openenv_version }}
GITHUB_EVENT_INPUTS_COLLECTION_NAMESPACE: ${{ github.event.inputs.collection_namespace }}
GITHUB_EVENT_INPUTS_PRIVATE: ${{ github.event.inputs.private }}
GITHUB_EVENT_INPUTS_SKIP_COLLECTION: ${{ github.event.inputs.skip_collection }}
GITHUB_EVENT_INPUTS_DRY_RUN: ${{ github.event.inputs.dry_run }}
Comment on lines +70 to +75

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Correct application of GitHub's recommended script-injection mitigation: these workflow_dispatch inputs are now referenced below as quoted shell variables ("${GITHUB_EVENT_INPUTS_…}") instead of being interpolated inline, and each name maps 1:1 to its use in the run: script (with set -u, a typo would fail loudly). Behavior is preserved.

Minor / non-blocking: the GITHUB_ prefix is reserved by GitHub for built-in variables. These specific names aren't among the default GITHUB_* vars, so they work in an inline env: block — but the prefix is discouraged, and names like these are rejected outright if ever moved to repository/environment variables or secrets. This file already uses the un-prefixed ENVS_CSV_INPUT (line 69) for the same purpose; matching that convention (e.g. HF_NAMESPACE_INPUT, OPENENV_VERSION_INPUT, …) would be more robust and consistent.

run: |
set -euo pipefail
chmod +x scripts/prepare_hf_deployment.sh

cmd=(scripts/prepare_hf_deployment.sh
--hf-namespace "${{ github.event.inputs.hf_namespace }}"
--openenv-version "${{ github.event.inputs.openenv_version }}"
--collection-namespace "${{ github.event.inputs.collection_namespace }}"
--hf-namespace "${GITHUB_EVENT_INPUTS_HF_NAMESPACE}"
--openenv-version "${GITHUB_EVENT_INPUTS_OPENENV_VERSION}"
--collection-namespace "${GITHUB_EVENT_INPUTS_COLLECTION_NAMESPACE}"
)

if [ "${{ github.event.inputs.private }}" = "true" ]; then
if [ "${GITHUB_EVENT_INPUTS_PRIVATE}" = "true" ]; then
cmd+=(--private)
else
cmd+=(--public)
fi

if [ "${{ github.event.inputs.skip_collection }}" = "true" ]; then
if [ "${GITHUB_EVENT_INPUTS_SKIP_COLLECTION}" = "true" ]; then
cmd+=(--skip-collection)
fi

if [ "${{ github.event.inputs.dry_run }}" = "true" ]; then
if [ "${GITHUB_EVENT_INPUTS_DRY_RUN}" = "true" ]; then
cmd+=(--dry-run)
fi

Expand Down
4 changes: 3 additions & 1 deletion .github/workflows/openspiel_base_build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -104,5 +104,7 @@ jobs:
- name: Build summary
run: |
echo "✅ OpenSpiel base image built and pushed successfully!"
echo "📦 Image: ${{ steps.meta-openspiel-base.outputs.tags }}"
echo "📦 Image: ${STEPS_META_OPENSPIEL_BASE_OUTPUTS_TAGS}"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Behavior-preserving and correct — the tag is now referenced as a quoted shell variable backed by the env: entry below. Since steps.meta-openspiel-base.outputs.tags is generated by docker/metadata-action (not user input), this is consistency hardening rather than a fix for an exploitable vector. The env var name here avoids the reserved GITHUB_ prefix, so no change needed.

echo "🚀 Next regular build will use this new base image"
env:
STEPS_META_OPENSPIEL_BASE_OUTPUTS_TAGS: ${{ steps.meta-openspiel-base.outputs.tags }}
Loading