Skip to content

Harden plugin test workflow slug handling - #6

Open
marktopper wants to merge 1 commit into
vitodeploy:add-unit-test-supportfrom
marktopper:fix/plugin-test-workflow-shell-injection
Open

marktopper wants to merge 1 commit into
vitodeploy:add-unit-test-supportfrom
marktopper:fix/plugin-test-workflow-shell-injection

Conversation

@marktopper

@marktopper marktopper commented Oct 3, 2026 •

Copy link
Copy Markdown
Member

Summary

Follow-up to #4. Keep changed plugin slugs out of shell command interpolation by passing them through an environment variable and parsing that value inside the Node runner. This prevents shell metacharacters in PR-controlled path components from being interpreted as commands.

The runner splits the environment value on whitespace, preserving changed-plugin selection behavior (including testing all plugins when the value is empty).

Verification

  • npm run validate
  • node --check scripts/test.mjs
  • git diff --check
  • Fixture-based runner check confirmed multiple env-provided slugs are dispatched separately.

The full PHPUnit suite could not be run because the clean Vito 4.x checkout has no Composer dependencies installed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant