Commit ba0c5264 authored by Victor Zagorodny's avatar Victor Zagorodny

Make propagate_env_vars scan regex more secure

parent 8c3c865d
...@@ -31,7 +31,7 @@ sast: ...@@ -31,7 +31,7 @@ sast:
CURRENT_ENV=$(printenv) CURRENT_ENV=$(printenv)
for VAR_NAME; do for VAR_NAME; do
echo $CURRENT_ENV | grep $VAR_NAME > /dev/null && echo "--env $VAR_NAME " echo $CURRENT_ENV | grep "${VAR_NAME}=" > /dev/null && echo "--env $VAR_NAME "
done done
} }
- export SP_VERSION=$(echo "$CI_SERVER_VERSION" | sed 's/^\([0-9]*\)\.\([0-9]*\).*/\1-\2-stable/') - export SP_VERSION=$(echo "$CI_SERVER_VERSION" | sed 's/^\([0-9]*\)\.\([0-9]*\).*/\1-\2-stable/')
...@@ -75,7 +75,7 @@ dependency_scanning: ...@@ -75,7 +75,7 @@ dependency_scanning:
CURRENT_ENV=$(printenv) CURRENT_ENV=$(printenv)
for VAR_NAME; do for VAR_NAME; do
echo $CURRENT_ENV | grep $VAR_NAME > /dev/null && echo "--env $VAR_NAME " echo $CURRENT_ENV | grep "${VAR_NAME}=" > /dev/null && echo "--env $VAR_NAME "
done done
} }
- | - |
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment