Woodpecker CI 3.19 fixes security vulnerability and improves task execution

Woodpecker CI 3.19 fixes security vulnerability and improves task execution

# woodpeckerci# ci# go
Woodpecker CI 3.19 fixes security vulnerability and improves task executionHacks.gr

Woodpecker CI 3.19 fixes a flaw that could allow environment variables from matrix settings to be injected into the default repository checkout step. The r

Woodpecker CI 3.19 fixes a flaw that could allow environment variables from matrix settings to be injected into the default repository checkout step.

The release also improves redaction of sensitive information in CLI task logs and adds administrator-enforced runner labels.


Changes in task execution

The security issue could allow the default code capture step to pass values ​​from settings that vary depending on the test combination. Version 3.19 also improves how sensitive information is hidden when executing tasks from the command line to reduce the risk of it appearing in logs.

Administrators can now define tags that must be present on machines running tasks. The platform also provides information about the identity and tags of each machine when a task is run. In local execution, a different path can now be used for the program that executes commands. A default setting for the user running tasks has also been added, which can be changed to run tasks without administrator privileges.

Fixes and improvements

The update fixes an issue that could cause logs to disappear when a job completed with skipped steps. It also fixes issues with simultaneous saving of settings and allows jobs to be restarted after errors that occur before their settings are saved. The platform no longer crashes when displaying a workflow with no steps.

This includes fixes for connecting to Bitbucket Cloud and GitLab, as well as using the platform in Kubernetes. In local execution, we fixed an issue that could cause the machine to stop if a job was canceled before its first step started. We also disabled some automatic Windows commands and improved the shutdown of execution machines.

The release also updates Go to version 1.27 and refreshes many of the project's dependencies.


Read the original English article on Hacks.gr