The current get-version workflow is implemented as:
[[workflows.steps]]
type = "Command"
command = 'echo "$version"'
However, this could give malformed output if $version happens to contain any syntax like ". This may not seem very likely for a version,1 however consider an equivalent workflow to print $changelog.
I attempted to workaround limitations with:
[[workflows.steps]]
type = "Command"
shell = true
command = """
cat <<EOF
$changelog
EOF
"""
however, that has its own issues:
- It relies on the current
SHELL being POSIX-compatible
- Even heredocs still have syntax, such as
`-backtick command substitution
For example, if I use the above command while fish is my default shell, I get:
fish: Expected a string, but found a redirection
cat <<EOF
^
or, using bash, if I have a changelog entry like:
- Added `/*nixfmt:disable*/` and `/*nixfmt:enable*/` comment directives to exclude regions of code from formatting
I see:
/nix/store/90nk33c4fkyg4x4dfk5cykqiryf2nlqq-bash-interactive-5.3p15/bin/bash: line 1: /*nixfmt:disable*/: No such file or directory
/nix/store/90nk33c4fkyg4x4dfk5cykqiryf2nlqq-bash-interactive-5.3p15/bin/bash: line 1: /*nixfmt:enable*/: No such file or directory
- Added and comment directives to exclude regions of code from formatting
Proposed solution
- We could add a
Print command type, which prints a literal template (with access to variables), similar to CreatePullRequest's body template.
- We could make variables available as shell-variables, allowing shell-native variable expansion like
"$version" or "$changelog".
The current
get-versionworkflow is implemented as:However, this could give malformed output if
$versionhappens to contain any syntax like". This may not seem very likely for a version,1 however consider an equivalent workflow to print$changelog.I attempted to workaround limitations with:
however, that has its own issues:
SHELLbeing POSIX-compatible`-backtick command substitutionFor example, if I use the above command while
fishis my default shell, I get:or, using
bash, if I have a changelog entry like:I see:
Proposed solution
Printcommand type, which prints a literaltemplate(with access tovariables), similar toCreatePullRequest's body template."$version"or"$changelog".Footnotes
Although it could be a string-escape security vulnerability, depending on how
knope get-versionis used in CI. Especially ifshell = trueis used. ↩