From 79df3a20f68c0135bb0a1a18331c286284c2b33d Mon Sep 17 00:00:00 2001 From: "aikido-autofix[bot]" <119856028+aikido-autofix[bot]@users.noreply.github.com> Date: Mon, 23 Mar 2026 22:02:56 +0000 Subject: [PATCH] fix(security): autofix Template Injection in GitHub Workflows Action --- .github/actions/setup-builder/action.yaml | 13 ++++++++----- 1 file changed, 8 insertions(+), 5 deletions(-) diff --git a/.github/actions/setup-builder/action.yaml b/.github/actions/setup-builder/action.yaml index 61faa055b1..73b50e0574 100644 --- a/.github/actions/setup-builder/action.yaml +++ b/.github/actions/setup-builder/action.yaml @@ -31,12 +31,15 @@ runs: steps: - name: Setup Rust Toolchain shell: bash + env: + RUST_VERSION: ${{ inputs.rust-version }} + TARGETS: ${{ inputs.targets }} run: | - echo "Installing ${{ inputs.rust-version }}" - if [ -n "${{ inputs.targets}}" ]; then - rustup toolchain install ${{ inputs.rust-version }} -t ${{ inputs.targets }} + echo "Installing $RUST_VERSION" + if [ -n "$TARGETS" ]; then + rustup toolchain install $RUST_VERSION -t $TARGETS else - rustup toolchain install ${{ inputs.rust-version }} + rustup toolchain install $RUST_VERSION fi - rustup default ${{ inputs.rust-version }} + rustup default $RUST_VERSION rustup component add rustfmt clippy