From df904c0249ee9fb84430e5fc4549b81f2a1fc93c Mon Sep 17 00:00:00 2001 From: Michael Geers Date: Tue, 14 Oct 2025 09:28:05 +0200 Subject: [PATCH] chore: proper escaping, see #24300, third try --- .github/workflows/language-reminder.yml | 14 ++++++++++++-- 1 file changed, 12 insertions(+), 2 deletions(-) diff --git a/.github/workflows/language-reminder.yml b/.github/workflows/language-reminder.yml index 460b42497..47cf2ea70 100644 --- a/.github/workflows/language-reminder.yml +++ b/.github/workflows/language-reminder.yml @@ -23,14 +23,24 @@ jobs: steps: - uses: actions/checkout@v5 + - name: Prepare input + id: prepare + shell: bash + env: + COMMENT_BODY: ${{ github.event.comment.body }} + run: | + # Use environment variable for security (prevents injection) + # Write comment to file to avoid YAML escaping issues + printf '%s' "$COMMENT_BODY" > /tmp/comment.txt + - name: Check language id: language_check uses: actions/ai-inference@v2 with: model: openai/gpt-4o-mini prompt-file: .github/prompts/language-check.prompt.yml - input: | - comment: ${{ toJson(github.event.comment.body) }} + file_input: | + comment: /tmp/comment.txt - name: Post reminder if non-English if: steps.language_check.outputs.response != ''