Skip to content

fix(workspace-plugin): epic generator command injection - #36702

Open
Paul Mardling (PaulGMardling) wants to merge 1 commit into
microsoft:masterfrom
PaulGMardling:fix/epic-generator-command-injection
Open

fix(workspace-plugin): epic generator command injection#36702
Paul Mardling (PaulGMardling) wants to merge 1 commit into
microsoft:masterfrom
PaulGMardling:fix/epic-generator-command-injection

Conversation

@PaulGMardling

@PaulGMardling Paul Mardling (PaulGMardling) commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Previous Behavior

The epic generator constructed GitHub CLI commands as shell strings. Repository and title values could therefore affect shell command parsing.

Repository validation was also not anchored, allowing invalid repository strings with additional characters to pass validation.

New Behavior

The generator now invokes the GitHub CLI with an executable and argument array, so repository names, titles, and generated issue content are handled as literal arguments rather than shell syntax.

Repository validation now requires the complete input to match the expected GitHub owner/repository format.

Regression tests cover malformed repository values and shell-like title input.

Fixes(s)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown

📊 Bundle size report

✅ No changes found

@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown

Pull request demo site: URL

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant