Skip to content

MAINT: Fix two cases of code injection via template expansion#39

Open
agriyakhetarpal wants to merge 1 commit intonumpy:mainfrom
agriyakhetarpal:zizmor-reports-31032026
Open

MAINT: Fix two cases of code injection via template expansion#39
agriyakhetarpal wants to merge 1 commit intonumpy:mainfrom
agriyakhetarpal:zizmor-reports-31032026

Conversation

@agriyakhetarpal
Copy link
Copy Markdown

This PR fixes two cases of template injection that Zizmor caught, from a local run.

cc: @rgommers

@rgommers
Copy link
Copy Markdown
Member

Thanks @agriyakhetarpal. I'm not sure this is a valid concern for this repo, given that we don't run CI on PRs from anyone but release team and org admin members. So the reason to change this would be to make using zizmor easier.

@agriyakhetarpal
Copy link
Copy Markdown
Author

agriyakhetarpal commented Mar 31, 2026

Thanks @rgommers. Indeed, this only changes what I saw through zizmor. Running the tool locally occasionally might be a good idea, as I mentioned to you privately elsewhere, in the extremely unlikely event that this repository gets compromised (this is still an attack vector, though a tad difficult to exploit here). If you and the rest of the release team agree with this PR at some later point, please feel free to merge this from the command line as you like, or merge it manually.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants