Skip to content

fix(workspace-plugin): epic generator command injection - #36702

Open
Paul Mardling (PaulGMardling) wants to merge 2 commits into
microsoft:masterfrom
PaulGMardling:fix/epic-generator-command-injection
Open

Paul Mardling (PaulGMardling) wants to merge 2 commits into
microsoft:masterfrom
PaulGMardling:fix/epic-generator-command-injection

Conversation

@PaulGMardling

@PaulGMardling Paul Mardling (PaulGMardling) commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Previous Behavior

The epic generator constructed GitHub CLI commands as shell strings. Repository and title values could therefore affect shell command parsing.

Repository validation was also not anchored, allowing invalid repository strings with additional characters to pass validation.

New Behavior

The generator now invokes the GitHub CLI with an executable and argument array, so repository names, titles, and generated issue content are handled as literal arguments rather than shell syntax.

Repository validation now requires the complete input to match the expected GitHub owner/repository format.

Regression tests cover malformed repository values and shell-like title input.

Fixes(s)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown

📊 Bundle size report

✅ No changes found

@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown

Pull request demo site: URL

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The security fix is correctly implemented and covered by focused regression tests.

Pull request overview

Replaces shell-string GitHub CLI execution with argument-array invocation and strengthens repository validation.

Changes:

  • Uses execFileSync to prevent command injection.
  • Anchors repository-name validation.
  • Adds regression tests for malformed repositories and special-character titles.

Review confidence: 100/100

File summaries
File Description
tools/workspace-plugin/src/generators/epic-generator/index.ts Secures GitHub CLI calls and repository validation.
tools/workspace-plugin/src/generators/epic-generator/index.spec.ts Verifies validation and literal argument handling.
Review details
  • Files reviewed: 2/2 changed files
  • Comments generated: 0
  • Review effort level: Balanced

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants