Verify branch-based workflow script injections don't work #2
Open
Description
Including code in the branch name and triggering a workflow run may result in arbitrary command execution due to github's templates not being escaped automatically.
Metadata
Assignees
Labels
Type
Projects
Status
Todo