{"id":"GHSA-7f32-hm4h-w77q","aliases":[],"url":"https://o3.security/vulnerability/GHSA-7f32-hm4h-w77q","summary":"github-slug-action use of `set-env` Runner commands which are processed via stdout","details":"### Impact\nThis GitHub Action use `set-env` runner commands which are processed via stdout related to GHSA-mfwh-5m23-j46w\n\n### Patches\nThe following versions use the recommended [Environment File Syntax](https://github.com/actions/toolkit/blob/main/docs/commands.md#environment-files).\n\n- 2.1.1\n- 1.1.1\n\n### Workarounds\nNone, it is strongly suggested that you upgrade as soon as possible.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [rlespinasse/github-slug-action](https://github.com/rlespinasse/github-slug-action)\n","published":"2024-02-03T00:22:22Z","modified":"2024-04-22T18:47:56Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"GitHub Actions","name":"rlespinasse/github-slug-action","fixedVersion":"1.1.1"},{"ecosystem":"GitHub Actions","name":"rlespinasse/github-slug-action","fixedVersion":"2.1.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/rlespinasse/github-slug-action/security/advisories/GHSA-7f32-hm4h-w77q"},{"type":"PACKAGE","url":"https://github.com/rlespinasse/github-slug-action"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-04-22T18:47:56Z"}}