fix(workspace-plugin): epic generator command injection - #36702
Open
Paul Mardling (PaulGMardling) wants to merge 1 commit into
Open
fix(workspace-plugin): epic generator command injection#36702Paul Mardling (PaulGMardling) wants to merge 1 commit into
Paul Mardling (PaulGMardling) wants to merge 1 commit into
Conversation
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Paul Mardling (PaulGMardling)
requested a review
from a team
as a code owner
September 7, 2026 08:33
📊 Bundle size report✅ No changes found |
|
Pull request demo site: URL |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Previous Behavior
The epic generator constructed GitHub CLI commands as shell strings. Repository and title values could therefore affect shell command parsing.
Repository validation was also not anchored, allowing invalid repository strings with additional characters to pass validation.
New Behavior
The generator now invokes the GitHub CLI with an executable and argument array, so repository names, titles, and generated issue content are handled as literal arguments rather than shell syntax.
Repository validation now requires the complete input to match the expected GitHub owner/repository format.
Regression tests cover malformed repository values and shell-like title input.
Fixes(s)