• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

yext / answers-search-ui
62%
master: 62%

Build:
Build:
LAST BUILD BRANCH: hotfix/v1.14.4
DEFAULT BRANCH: master
Repo Added 06 May 2021 04:33PM UTC
Files 166
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

LAST BUILD ON BRANCH hotfix/fix-run-shell-injection
branch: hotfix/fix-run-shell-injection
CHANGE BRANCH
x
Reset
  • hotfix/fix-run-shell-injection
  • PhilipA20-patch-1
  • codelab-answers-core
  • dependabot/npm_and_yarn/babel/plugin-proposal-object-rest-spread-7.14.7
  • dependabot/npm_and_yarn/babel/runtime-corejs3-7.14.7
  • dependabot/npm_and_yarn/color-string-1.6.0
  • dependabot/npm_and_yarn/cross-fetch-3.1.4
  • dependabot/npm_and_yarn/elliptic-6.5.4
  • dependabot/npm_and_yarn/fs-extra-10.0.0
  • dependabot/npm_and_yarn/gulp-sass-5.0.0
  • dependabot/npm_and_yarn/hosted-git-info-2.8.9
  • dependabot/npm_and_yarn/i18next-20.3.2
  • dependabot/npm_and_yarn/i18next-conv-10.2.0
  • dependabot/npm_and_yarn/percy/testcafe-1.0.1
  • dependabot/npm_and_yarn/postcss-pxtorem-5.1.1
  • dependabot/npm_and_yarn/rollup-plugin-commonjs-10.1.0
  • dependabot/npm_and_yarn/sass-1.37.0
  • dependabot/npm_and_yarn/serve-12.0.0
  • dependabot/npm_and_yarn/stylelint-scss-3.19.0
  • dependabot/npm_and_yarn/types/jest-26.0.24
  • dev/fix-acceptance
  • dev/gda-endpoint-flow
  • dev/gda-include-full-entity-data-in-citations
  • dev/gda-object-model
  • dev/gda-result-component
  • dev/merge-v1.18.0-0cfd321-into-develop
  • dev/merge-v1.18.1-785c3e4-into-develop
  • dev/merge-v1.18.1-9c77d9b-into-develop
  • dev/merge-v1.18.2-6fc8890-into-develop
  • dev/merge-v1.18.3-24289af-into-develop
  • dev/merge-v1.18.4-05c3b5e-into-develop
  • dev/test-reusable-workflows
  • dev/update-semgrep-action-ubuntu-latest
  • dev/upgrade-node
  • dev/v1.17.8
  • develop
  • early-access-spring-22
  • early-access-summer-21
  • feature/DA-on-vertical-search
  • feature/DirectAnswer-in-Vertical
  • feature/add-locales
  • feature/arabic-i18n
  • feature/arabic-test-i18n
  • feature/auth-and-visitor
  • feature/case-deflection
  • feature/chinese-i18n
  • feature/develop-i18n
  • feature/email-error-translations
  • feature/gh-action-migration
  • feature/gh-action-migration-rebase
  • feature/icon-partial-i18n
  • feature/missing-translations
  • feature/rebase-search-bar
  • feature/rebased-standalone-search-bar
  • feature/speech-recognition
  • feature/summer-languages
  • feature/universal-autocomplete-fixtures
  • feature/universal-fixture
  • gda-develop
  • gda-develop/adjust-custom-card-logic
  • hotfix/1.15.5
  • hotfix/1.15.6
  • hotfix/1.16.1
  • hotfix/fix-run-shell-injection-2
  • hotfix/search-bar/v1.1.1
  • hotfix/should-deploy-next-minor-fix
  • hotfix/update-searchbar-only-test
  • hotfix/update-validate-config
  • hotfix/v1.10.1
  • hotfix/v1.10.1-rebased
  • hotfix/v1.11.1
  • hotfix/v1.12.1
  • hotfix/v1.12.1-test
  • hotfix/v1.12.2
  • hotfix/v1.12.3
  • hotfix/v1.12.4
  • hotfix/v1.13.1
  • hotfix/v1.14.1
  • hotfix/v1.14.2
  • hotfix/v1.14.3
  • hotfix/v1.14.4
  • hotfix/v1.15.1
  • hotfix/v1.15.2
  • hotfix/v1.15.3
  • hotfix/v1.15.4
  • hotfix/v1.15.5
  • hotfix/v1.15.6
  • hotfix/v1.16.1
  • hotfix/v1.16.2
  • hotfix/v1.16.3
  • hotfix/v1.16.4
  • hotfix/v1.16.5
  • hotfix/v1.16.6
  • hotfix/v1.16.7
  • hotfix/v1.16.8
  • hotfix/v1.17.1
  • hotfix/v1.17.2
  • hotfix/v1.17.3
  • hotfix/v1.17.4
  • hotfix/v1.17.5
  • hotfix/v1.17.6
  • hotfix/v1.17.7
  • hotfix/v1.17.8
  • hotfix/v1.17.9
  • hotfix/v1.18.1-b1/gda-empty-search-and-error-display
  • hotfix/v1.18.2
  • hotfix/v1.18.3
  • hotfix/v1.18.4
  • hotfix/v1.18.5
  • hotfix/v1.18.6
  • hotfix/v1.18.7
  • hotfix/v1.2.3
  • hotfix/v1.8.4
  • hotfix/v1.9.1
  • hotfix/v1.9.2
  • hotfixv1.16.4
  • hotifx/v1.10.1
  • main
  • master
  • patch/v1.10.1
  • release/1.15.6
  • release/v1.10.0
  • release/v1.11
  • release/v1.12
  • release/v1.13
  • release/v1.14
  • release/v1.14.4
  • release/v1.15.6
  • release/v1.16.8
  • release/v1.17
  • release/v1.17.9
  • release/v1.9
  • revert-1668-dev/bypass-fail-nearme-request
  • rparchuri-patch-1
  • rparchuri-patch-2
  • search-bar-v0.1.0
  • search-bar-v9.9.9
  • search-bar/hotfix/v1.1.1
  • snyk-fix-07647e4801372b1dcc5e392eed3d496a
  • snyk-upgrade-00c45464e83a3e692e87ef8bf8ead8bf
  • snyk-upgrade-01f02148fe192955936ffbc257e46994
  • snyk-upgrade-0a8d378305f0d45b46af2aa8204166e4
  • snyk-upgrade-0ac46766d091148daa2b731fd0d0daec
  • snyk-upgrade-0ef4bb78729236c3048b8fcd5a9d7462
  • snyk-upgrade-10f9c0718dbcbee2cc1ea0e1684f12d4
  • snyk-upgrade-12d6e8bf3863654a677d88c99ecd5c41
  • snyk-upgrade-13add925e961f12f11fe06566fbb4c3f
  • snyk-upgrade-15e4a99c1c6669ac1751927349792262
  • snyk-upgrade-1b7bb487db62cd35f454261dea4e57bd
  • snyk-upgrade-25aab12a890005e6e9a52e4acd7b0b0e
  • snyk-upgrade-27adb644fe651fcee397c7e6f57b98dc
  • snyk-upgrade-2d71d52b0c9acee68856d4b3521386b8
  • snyk-upgrade-2e1371ce51194b26a6ea9896e955e753
  • snyk-upgrade-3576aaec46cde62fae202bfc9ef75bb4
  • snyk-upgrade-39304731140e9dd6e4cace2fed752704
  • snyk-upgrade-3bd029307ab84a9819375090abb9509c
  • snyk-upgrade-431836fd5ea40b0d2a1e9f504b9050a1
  • snyk-upgrade-432c1c3bbc47bb290aad8f5c1d82d355
  • snyk-upgrade-44bbbdac500e5b3f6cc7fa90d89ad221
  • snyk-upgrade-46fb0dbd4cd251fe9ce4f643a912923f
  • snyk-upgrade-4c5f948491153135bc8a354eb7459177
  • snyk-upgrade-51758367705b9c79bb5fc083c0715e9c
  • snyk-upgrade-5951c77f6bd9621995e06f4931a8328e
  • snyk-upgrade-68e07ef071d139961fa09f18db070ae3
  • snyk-upgrade-69a4522d4e86b83f6bcf361e715bff21
  • snyk-upgrade-6f78fbadf86d63a9a86cf25b1246ad05
  • snyk-upgrade-73b73cac1b6587622c7cdc04e119a159
  • snyk-upgrade-765637ce30acb246edf4130742faca8a
  • snyk-upgrade-77f78c487f13b45cf4cb049dd4b9099a
  • snyk-upgrade-86dfe3925cc2701a3e79f38bf6f63677
  • snyk-upgrade-870173f639942b3d99c7e67b2425a7ca
  • snyk-upgrade-97001d73a0af219ff04c712ef2d86a61
  • snyk-upgrade-a24d721a7fdd384c703acd2442a1f92b
  • snyk-upgrade-b333256a546c13f2b002d66debe3bda0
  • snyk-upgrade-b3fc5dcf22ad458b6ca457ed45db9a4e
  • snyk-upgrade-b5c812c47dd4020d09f4af8dc38ef455
  • snyk-upgrade-c3e7fa5e4e18cc80e131ab7bf17b345d
  • snyk-upgrade-c7624fbd85322fb9c4d64429f0e5b147
  • snyk-upgrade-c9253d1bd32408f3c52f64b0defbffe3
  • snyk-upgrade-caeb2b8fc204372a462bae76ffc5edf7
  • snyk-upgrade-cbaeea51dfb77d703f2480299f420e5f
  • snyk-upgrade-cf2ee48363d1817145ef35faa5f18843
  • snyk-upgrade-d256016a3a5618d329287c233050d3b9
  • snyk-upgrade-d2f336971d5f3d12040cc816bdd18b4b
  • snyk-upgrade-e471a1abf2473d0485a512b441de4b9e
  • snyk-upgrade-e5baab7a8e79078713c569e82f5a9897
  • snyk-upgrade-e9d17cdc3caa4c46988f4f039a8a76f4
  • snyk-upgrade-fb6b365d054ad5d5a2b9983ce2351fb4
  • support/search-bar-v1.1
  • support/search-bar-v1.2
  • support/test-gh-actions
  • support/test-misc-tests
  • support/test-workflow-non-i8n-build
  • support/v1.10
  • support/v1.11
  • support/v1.12
  • support/v1.13
  • support/v1.9
  • test-coverage-node-20
  • test/netlify
  • test/node-20-workflows
  • test/v0.1.2
  • tmeyer2115-patch-1
  • tmeyer2115-patch-2
  • update-translations
  • update-visitor-readme
  • v1.16.0
  • wcag-ci-test

17 Mar 2025 06:13PM UTC coverage: 61.773%. Remained the same
13907161417

Pull #1924

github

mkouzel-yext
Remove run shell injection vulnerability

Prevents attackers from injecting their own code into the github actions runner using variable interpolation to steal screts and code. We now use an intermediate environment variable to store input data.
Pull Request #1924: Remove run shell injection vulnerability

2029 of 3433 branches covered (59.1%)

Branch coverage included in aggregate %.

3483 of 5490 relevant lines covered (63.44%)

26.64 hits per line

Relevant lines Covered
Build:
Build:
5490 RELEVANT LINES 3483 COVERED LINES
26.64 HITS PER LINE
Source Files on hotfix/fix-run-shell-injection
  • Tree
  • List 170
  • Changed 0
  • Source Changed 0
  • Coverage Changed 0
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses

Recent builds

Builds Branch Commit Type Ran Committer Via Coverage
13907161417 hotfix/fix-run-shell-injection Remove run shell injection vulnerability Prevents attackers from injecting their own code into the github actions runner using variable interpolation to steal screts and code. We now use an intermediate environment variable to store input data. Pull #1924 17 Mar 2025 06:33PM UTC mkouzel-yext github
61.77
See All Builds (1946)
  • Repo on GitHub
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2025 Coveralls, Inc