-
Notifications
You must be signed in to change notification settings - Fork 18
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
action: prevent globbing with double quotes #68
Conversation
This patch adds double quotes on variables to prevent globbing and prevent evaluation errors such as: line 1: [: =: unary operator expected It also add consistency on bash string equality comparison by using `==` operator instead of `=`. Signed-off-by: Luís Ferreira <contact@lsferreira.net>
CC @lolgab |
@ljmf00: "==" is not POSIX compliant and also it won't make any difference in single brackets. |
The usage of non-POSIX complaint features is not a problem here, since the action uses the As the commit message suggested, these changes were to improve consistency in one way or another and not about the usefulness of equality/pattern matching in |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
What do you mean? |
…114) This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [codacy/codacy-analysis-cli-action](https://github.com/codacy/codacy-analysis-cli-action) | action | patch | `v4.4.1` -> `v4.4.4` | --- ### Release Notes <details> <summary>codacy/codacy-analysis-cli-action (codacy/codacy-analysis-cli-action)</summary> ### [`v4.4.4`](https://github.com/codacy/codacy-analysis-cli-action/releases/tag/v4.4.4) [Compare Source](https://github.com/codacy/codacy-analysis-cli-action/compare/v4.4.3...v4.4.4) #### What's Changed - update cli version to 7.9.11 by [@​hjrocha](https://github.com/hjrocha) in [https://github.com/codacy/codacy-analysis-cli-action/pull/132](https://github.com/codacy/codacy-analysis-cli-action/pull/132) ### [`v4.4.3`](https://github.com/codacy/codacy-analysis-cli-action/releases/tag/v4.4.3) [Compare Source](https://github.com/codacy/codacy-analysis-cli-action/compare/v4.4.2...v4.4.3) #### What's Changed - fix registry-address default value by [@​hjrocha](https://github.com/hjrocha) in [https://github.com/codacy/codacy-analysis-cli-action/pull/131](https://github.com/codacy/codacy-analysis-cli-action/pull/131) ### [`v4.4.2`](https://github.com/codacy/codacy-analysis-cli-action/releases/tag/v4.4.2) [Compare Source](https://github.com/codacy/codacy-analysis-cli-action/compare/v4.4.1...v4.4.2) #### What's Changed - Fixed some broken links by [@​mushlih-almubarak](https://github.com/mushlih-almubarak) in [https://github.com/codacy/codacy-analysis-cli-action/pull/77](https://github.com/codacy/codacy-analysis-cli-action/pull/77) - bump: Bump codacy-analysis-cli to 7.6.4 CY-6112 by [@​lolgab](https://github.com/lolgab) in [https://github.com/codacy/codacy-analysis-cli-action/pull/80](https://github.com/codacy/codacy-analysis-cli-action/pull/80) - feature: Introduce new versioning scheme `vX.X.X` by [@​lolgab](https://github.com/lolgab) in [https://github.com/codacy/codacy-analysis-cli-action/pull/81](https://github.com/codacy/codacy-analysis-cli-action/pull/81) - doc: Mention setting up the Go environment DOCS-380 by [@​prcr](https://github.com/prcr) in [https://github.com/codacy/codacy-analysis-cli-action/pull/83](https://github.com/codacy/codacy-analysis-cli-action/pull/83) - \[SE-140] Add max-tool-memory flag by [@​heliocodacy](https://github.com/heliocodacy) in [https://github.com/codacy/codacy-analysis-cli-action/pull/86](https://github.com/codacy/codacy-analysis-cli-action/pull/86) - Bump gosec to v2.13.1 CY-6239 by [@​stefanvacareanu7](https://github.com/stefanvacareanu7) in [https://github.com/codacy/codacy-analysis-cli-action/pull/87](https://github.com/codacy/codacy-analysis-cli-action/pull/87) - Fix typo by [@​pSub](https://github.com/pSub) in [https://github.com/codacy/codacy-analysis-cli-action/pull/82](https://github.com/codacy/codacy-analysis-cli-action/pull/82) - doc: Bump supported Go version to 1.19.1 CY-6239 by [@​prcr](https://github.com/prcr) in [https://github.com/codacy/codacy-analysis-cli-action/pull/88](https://github.com/codacy/codacy-analysis-cli-action/pull/88) - Update supported languages count by [@​nicklem](https://github.com/nicklem) in [https://github.com/codacy/codacy-analysis-cli-action/pull/91](https://github.com/codacy/codacy-analysis-cli-action/pull/91) - doc: Improve CLI parameters DOCS-180 by [@​nicklem](https://github.com/nicklem) in [https://github.com/codacy/codacy-analysis-cli-action/pull/92](https://github.com/codacy/codacy-analysis-cli-action/pull/92) - doc: Flag [@​codacy/techwriters](https://github.com/codacy/techwriters) as owners of README.md DOCS-483 by [@​nicklem](https://github.com/nicklem) in [https://github.com/codacy/codacy-analysis-cli-action/pull/93](https://github.com/codacy/codacy-analysis-cli-action/pull/93) - added github_token in all requests to github api in action.yml by [@​DMarinhoCodacy](https://github.com/DMarinhoCodacy) in [https://github.com/codacy/codacy-analysis-cli-action/pull/96](https://github.com/codacy/codacy-analysis-cli-action/pull/96) - removed github-token from action.yaml file by [@​DMarinhoCodacy](https://github.com/DMarinhoCodacy) in [https://github.com/codacy/codacy-analysis-cli-action/pull/100](https://github.com/codacy/codacy-analysis-cli-action/pull/100) - changed staticcheck URL using github api to artifact TS-214 by [@​DMarinhoCodacy](https://github.com/DMarinhoCodacy) in [https://github.com/codacy/codacy-analysis-cli-action/pull/102](https://github.com/codacy/codacy-analysis-cli-action/pull/102) - updated Clang-Tidy URL to artifact by [@​DMarinhoCodacy](https://github.com/DMarinhoCodacy) in [https://github.com/codacy/codacy-analysis-cli-action/pull/103](https://github.com/codacy/codacy-analysis-cli-action/pull/103) - doc: Mention turning on and configuring the client-side tool by [@​prcr](https://github.com/prcr) in [https://github.com/codacy/codacy-analysis-cli-action/pull/106](https://github.com/codacy/codacy-analysis-cli-action/pull/106) - moved gosec and fauxpas to artifact by [@​DMarinhoCodacy](https://github.com/DMarinhoCodacy) in [https://github.com/codacy/codacy-analysis-cli-action/pull/107](https://github.com/codacy/codacy-analysis-cli-action/pull/107) - fix installation staticcheck using official binary by [@​DMarinhoCodacy](https://github.com/DMarinhoCodacy) in [https://github.com/codacy/codacy-analysis-cli-action/pull/108](https://github.com/codacy/codacy-analysis-cli-action/pull/108) - feature: allow skipping container engine check IO-423 by [@​pedrocodacy](https://github.com/pedrocodacy) in [https://github.com/codacy/codacy-analysis-cli-action/pull/110](https://github.com/codacy/codacy-analysis-cli-action/pull/110) - close if statement properly by [@​bjarkebm](https://github.com/bjarkebm) in [https://github.com/codacy/codacy-analysis-cli-action/pull/114](https://github.com/codacy/codacy-analysis-cli-action/pull/114) - bump cli version by [@​pedrocodacy](https://github.com/pedrocodacy) in [https://github.com/codacy/codacy-analysis-cli-action/pull/116](https://github.com/codacy/codacy-analysis-cli-action/pull/116) - doc: Update Codacy logo DOCS-594 by [@​nicklem](https://github.com/nicklem) in [https://github.com/codacy/codacy-analysis-cli-action/pull/119](https://github.com/codacy/codacy-analysis-cli-action/pull/119) - action: prevent globbing with double quotes by [@​ljmf00](https://github.com/ljmf00) in [https://github.com/codacy/codacy-analysis-cli-action/pull/68](https://github.com/codacy/codacy-analysis-cli-action/pull/68) - Bump cli, staticheck, gosec versions TCE-614 by [@​stefanvacareanu7](https://github.com/stefanvacareanu7) in [https://github.com/codacy/codacy-analysis-cli-action/pull/124](https://github.com/codacy/codacy-analysis-cli-action/pull/124) - TCE-937 add condition to setup go only if the user wants to run staticcheck by [@​DMarinhoCodacy](https://github.com/DMarinhoCodacy) in [https://github.com/codacy/codacy-analysis-cli-action/pull/126](https://github.com/codacy/codacy-analysis-cli-action/pull/126) - feat: \[TCE-1039] Add parameter 'registry-address' in order to support alternative registry addresses by [@​heliocodacy](https://github.com/heliocodacy) in [https://github.com/codacy/codacy-analysis-cli-action/pull/129](https://github.com/codacy/codacy-analysis-cli-action/pull/129) #### New Contributors - [@​mushlih-almubarak](https://github.com/mushlih-almubarak) made their first contribution in [https://github.com/codacy/codacy-analysis-cli-action/pull/77](https://github.com/codacy/codacy-analysis-cli-action/pull/77) - [@​stefanvacareanu7](https://github.com/stefanvacareanu7) made their first contribution in [https://github.com/codacy/codacy-analysis-cli-action/pull/87](https://github.com/codacy/codacy-analysis-cli-action/pull/87) - [@​pSub](https://github.com/pSub) made their first contribution in [https://github.com/codacy/codacy-analysis-cli-action/pull/82](https://github.com/codacy/codacy-analysis-cli-action/pull/82) - [@​nicklem](https://github.com/nicklem) made their first contribution in [https://github.com/codacy/codacy-analysis-cli-action/pull/91](https://github.com/codacy/codacy-analysis-cli-action/pull/91) - [@​DMarinhoCodacy](https://github.com/DMarinhoCodacy) made their first contribution in [https://github.com/codacy/codacy-analysis-cli-action/pull/96](https://github.com/codacy/codacy-analysis-cli-action/pull/96) - [@​bjarkebm](https://github.com/bjarkebm) made their first contribution in [https://github.com/codacy/codacy-analysis-cli-action/pull/114](https://github.com/codacy/codacy-analysis-cli-action/pull/114) - [@​ljmf00](https://github.com/ljmf00) made their first contribution in [https://github.com/codacy/codacy-analysis-cli-action/pull/68](https://github.com/codacy/codacy-analysis-cli-action/pull/68) **Full Changelog**: codacy/codacy-analysis-cli-action@4.0.2...v4.4.2 </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy40MjAuMSIsInVwZGF0ZWRJblZlciI6IjM3LjQyMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==--> Signed-off-by: Renovate Bot <bot@renovateapp.com> Co-authored-by: renovate-gsuquet[bot] <173481049+renovate-gsuquet[bot]@users.noreply.github.com>
This patch adds double quotes on variables to prevent globbing and prevent evaluation errors such as:
It also add consistency on bash string equality comparison by using
==
operator instead of
=
.Signed-off-by: Luís Ferreira contact@lsferreira.net
Since this is behaving "good" by accident, please double check if this doesn't break any specific use-case of this action. I recommend changing this to standalone scripts and passing GitHub variables by argument and parse them using something like POSIX getopt. See https://man7.org/linux/man-pages/man1/getopts.1p.html