fix(ci): store regex in variables to fix notify-parent parse error - #8
Conversation
|
No actionable comments were generated in the recent review. 🎉 WalkthroughA GitHub Actions workflow was updated to set event/payload environment variables, centralize the event name into EVENT_NAME, introduce a write_output helper for GITHUB_OUTPUT, replace inline echo/output writes with helper calls, and replace inline regex literals with named regex variables for commit-message type inference. Changes
Estimated code review effort🎯 2 (Simple) | ⏱️ ~10 minutes Poem
🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Greptile SummaryFixed bash parse error in notify-parent workflow by storing regex patterns in variables before using them in
Confidence Score: 5/5
|
| Filename | Overview |
|---|---|
| .github/workflows/notify-parent.yml | Fixed bash parse error by storing regex patterns in variables before using them in conditional tests |
Last reviewed commit: a6bc980
a6bc980 to
7561bbe
Compare
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In @.github/workflows/notify-parent.yml:
- Around line 30-50: The current writes like echo "repo=$PAYLOAD_REPO" >>
$GITHUB_OUTPUT (and the similar echo lines for PAYLOAD_REPO_NAME, PAYLOAD_SHA,
PAYLOAD_SHORT_SHA, PAYLOAD_MESSAGE, PAYLOAD_TYPE, PAYLOAD_ACTOR and the later
git log message) are vulnerable to newline injection because PAYLOAD_* values
can contain newlines; replace each echo-based write to $GITHUB_OUTPUT with
GitHub's safe multiline output pattern: use the heredoc/delimiter style that
appends to the quoted "$GITHUB_OUTPUT" with a unique delimiter per key and place
the untrusted value between the delimiters (i.e., emit the key header then the
delimiter block containing the raw value, then the closing delimiter) so
multiline payloads are preserved and cannot inject additional output lines.
Ensure every occurrence where you currently echo into $GITHUB_OUTPUT (including
the git log/commit message write) is converted to this safe delimiter/heredoc
approach.
7561bbe to
ea8ea6d
Compare
There was a problem hiding this comment.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Duplicate comments:
In @.github/workflows/notify-parent.yml:
- Around line 43-67: The write_output function currently uses a fixed heredoc
delimiter "__EOF__", which can be injected by untrusted values; change
write_output to generate a unique delimiter per call (e.g., random hex/uuid or
mktemp-based token) and use that token in the two delimiter printf lines instead
of "__EOF__", ensuring you write to "$GITHUB_OUTPUT" the same dynamically
generated delimiter for both the opening and closing heredoc; also guard by
regenerating the token if it appears in the value (or choose a sufficiently
random/long token) so the delimiter never collides with the key/value content.
Bash interprets `(` in `[:(]` character classes as an unmatched subshell opener, causing "unexpected EOF while looking for matching ')'" (exit code 2). Storing the regex in a variable avoids this because bash passes variable content directly to the regex engine without shell parsing. Resolves [[incidents/notify-parent-broken]] Implements [[tasks/meta-64]] Co-authored-by: Claude <claude@anthropic.com>
ea8ea6d to
ebc0112
Compare
#8) Bash interprets `(` in `[:(]` character classes as an unmatched subshell opener, causing "unexpected EOF while looking for matching ')'" (exit code 2). Storing the regex in a variable avoids this because bash passes variable content directly to the regex engine without shell parsing. Resolves [[incidents/notify-parent-broken]] Implements [[tasks/meta-64]] Co-authored-by: Claude <claude@anthropic.com>
Summary
[[ =~ ]]tests(in[:(]character class was interpreted as unmatched subshell openerunexpected EOF while looking for matching ')'(exit code 2)Root cause
Context
Test plan
🤖 Generated with Claude Code
Summary by CodeRabbit
Note: This release contains no user-facing changes.