From ef59de693f483271605ed3e5928d5e8075f129dd Mon Sep 17 00:00:00 2001 From: Charly Gomez Date: Tue, 24 Feb 2026 14:34:06 +0100 Subject: [PATCH] validate alert id --- .github/workflows/fix-security-vulnerability.yml | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/.github/workflows/fix-security-vulnerability.yml b/.github/workflows/fix-security-vulnerability.yml index 8edd1447ca9b..f78290c032c6 100644 --- a/.github/workflows/fix-security-vulnerability.yml +++ b/.github/workflows/fix-security-vulnerability.yml @@ -32,7 +32,13 @@ jobs: id: alert run: | INPUT="${{ github.event.inputs.alert }}" - echo "number=${INPUT##*/}" >> "$GITHUB_OUTPUT" + RAW="${INPUT##*/}" + NUMBER="${RAW%%\?*}" + if ! [[ "$NUMBER" =~ ^[0-9]+$ ]]; then + echo "Error: Could not extract a valid numeric alert ID from input: $INPUT" + exit 1 + fi + echo "number=$NUMBER" >> "$GITHUB_OUTPUT" - uses: anthropics/claude-code-action@v1 with: