Filed from an out-of-scope finding in the Hive review of PR #544.
PR: #544
Perspective: security
Evidence: .github/workflows/reusable-sync-branches.yml:158
Severity: low
Merge (126-134) and Force-reset (151-164) steps still interpolate inputs.source_branch/target_branch directly into shell. Inputs come from the trusted caller workflow so exploitability is low, but the PR's new steps use env vars; migrating the remaining steps would make the file consistent and remove the injection surface.
Filed from an out-of-scope finding in the Hive review of PR #544.
PR: #544
Perspective: security
Evidence:
.github/workflows/reusable-sync-branches.yml:158Severity: low
Merge (126-134) and Force-reset (151-164) steps still interpolate inputs.source_branch/target_branch directly into shell. Inputs come from the trusted caller workflow so exploitability is low, but the PR's new steps use env vars; migrating the remaining steps would make the file consistent and remove the injection surface.