Skip to content

chore: validate the release tag and build the scribe dispatch payload with jq - #193

Merged
spark2ignite merged 1 commit into
mainfrom
chore/release-tag-validation
Oct 1, 2026
Merged

spark2ignite merged 1 commit into
mainfrom
chore/release-tag-validation

Conversation

@spark2ignite

Copy link
Copy Markdown
Collaborator

Summary

Git allows " in tag names. release.yml built the repository_dispatch JSON for doiteng/scribe by pasting the tag into a string, so a crafted v* tag could add fields to the payload sent with SCRIBE_DISPATCH_TOKEN. This is the "Release dispatch JSON" follow-up listed in #191.

Changes

.github/workflows/release.yml

  • A new first step, "Validate release tag", runs before checkout. It rejects any tag that doesn't match ^v[0-9]+\.[0-9]+\.[0-9]+(-[0-9A-Za-z]+(\.[0-9A-Za-z]+)*)?$, the same pattern chore: stop release tag from reaching shell, sed, and manifests unvalidated #191 adds to sync-manifests.yml and post-release-verify.yml. A tag that passes is exported as RELEASE_TAG.
  • The changelog gate, the "Trigger downstream workflows" dispatches and the scribe step read $RELEASE_TAG. Nothing parses GITHUB_REF after the check any more.
  • The scribe payload is built with jq -cn --arg tag "$RELEASE_TAG" '{...}', so it's safe even without the check.

Testing

  • actionlint passes.
  • Every existing v* tag matches the pattern, and so does v2.8.0-rc.1.
  • The check rejects a ","client_payload":... injection, $(id), a tag with an embedded newline (which would otherwise add a line to GITHUB_ENV), and v1.2.3-...
  • jq produces the same JSON as the old payload for valid tags.
  • Not run on Actions. The next release tag will exercise it.

Note

The step's comment says the check matches the one in sync-manifests.yml and post-release-verify.yml. That's only true once #191 merges.

🤖 Generated with Claude Code

… with jq

Git allows " in tag names, so a crafted v* tag could add fields to the
repository_dispatch JSON sent to doiteng/scribe with SCRIBE_DISPATCH_TOKEN.
The release job now rejects tags outside vMAJOR.MINOR.PATCH[-PRERELEASE]
before checkout, later steps read the checked RELEASE_TAG, and the payload
is built with jq --arg.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@spark2ignite
spark2ignite requested review from a team, apgiorgi, chaim0m and taltultc as code owners October 1, 2026 16:16
@github-actions github-actions Bot added automation GitHub Actions and repository automation changes release Release configuration and publishing changes labels Oct 1, 2026

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good — straightforward CI hardening change.

What was reviewed: the new tag-validation regex and its placement (runs first, before checkout, so it gates every later step); the switch from three independent GITHUB_REF parses to a single RELEASE_TAG export; the scribe dispatch payload change from manual string interpolation to jq -cn, which closes the tag-injection risk the PR describes (a " in a tag could previously add fields to the client_payload). No issues found.

Extended reasoning...

Single-file change to .github/workflows/release.yml: adds a tag-format validation step and centralizes tag extraction into $RELEASE_TAG, and swaps manual JSON string-building for jq in the scribe repository_dispatch call. Security-sensitive surface is the untrusted-tag-to-JSON-payload path (a crafted tag could previously inject fields into a dispatch sent with a secret token); jq -cn with --arg correctly neutralizes that, and the new regex additionally rejects malformed/malicious tags up front. The change is small, mechanical, CI-only, matches the repo's chore: commit convention for non-user-facing CI fixes, and has no open reviewer objections in the PR timeline, so a human need not re-review.

@spark2ignite
spark2ignite merged commit fe9776b into main Oct 1, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automation GitHub Actions and repository automation changes release Release configuration and publishing changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant