fix(workspace-plugin): epic generator command injection - #36702
Open
Paul Mardling (PaulGMardling) wants to merge 2 commits into
Open
Paul Mardling (PaulGMardling) wants to merge 2 commits into
Paul Mardling (PaulGMardling) wants to merge 2 commits into
Conversation
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Paul Mardling (PaulGMardling)
requested a review
from a team
as a code owner
September 7, 2026 08:33
📊 Bundle size report✅ No changes found |
|
Pull request demo site: URL |
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot started reviewing on behalf of
Dmytro Kirpa (dmytrokirpa)
September 15, 2026 19:27
View session
Contributor
There was a problem hiding this comment.
🟢 Approval recommended
The security fix is correctly implemented and covered by focused regression tests.
Pull request overview
Replaces shell-string GitHub CLI execution with argument-array invocation and strengthens repository validation.
Changes:
- Uses
execFileSyncto prevent command injection. - Anchors repository-name validation.
- Adds regression tests for malformed repositories and special-character titles.
Review confidence: 100/100
File summaries
| File | Description |
|---|---|
tools/workspace-plugin/src/generators/epic-generator/index.ts |
Secures GitHub CLI calls and repository validation. |
tools/workspace-plugin/src/generators/epic-generator/index.spec.ts |
Verifies validation and literal argument handling. |
Review details
- Files reviewed: 2/2 changed files
- Comments generated: 0
- Review effort level: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Previous Behavior
The epic generator constructed GitHub CLI commands as shell strings. Repository and title values could therefore affect shell command parsing.
Repository validation was also not anchored, allowing invalid repository strings with additional characters to pass validation.
New Behavior
The generator now invokes the GitHub CLI with an executable and argument array, so repository names, titles, and generated issue content are handled as literal arguments rather than shell syntax.
Repository validation now requires the complete input to match the expected GitHub owner/repository format.
Regression tests cover malformed repository values and shell-like title input.
Fixes(s)