Commit ba0c5264 authored by Victor Zagorodny's avatar Victor Zagorodny

Make propagate_env_vars scan regex more secure

parent 8c3c865d
......@@ -31,7 +31,7 @@ sast:
CURRENT_ENV=$(printenv)
for VAR_NAME; do
echo $CURRENT_ENV | grep $VAR_NAME > /dev/null && echo "--env $VAR_NAME "
echo $CURRENT_ENV | grep "${VAR_NAME}=" > /dev/null && echo "--env $VAR_NAME "
done
}
- export SP_VERSION=$(echo "$CI_SERVER_VERSION" | sed 's/^\([0-9]*\)\.\([0-9]*\).*/\1-\2-stable/')
......@@ -75,7 +75,7 @@ dependency_scanning:
CURRENT_ENV=$(printenv)
for VAR_NAME; do
echo $CURRENT_ENV | grep $VAR_NAME > /dev/null && echo "--env $VAR_NAME "
echo $CURRENT_ENV | grep "${VAR_NAME}=" > /dev/null && echo "--env $VAR_NAME "
done
}
- |
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment