This document formalizes the security architecture, input trust model, shell command tokenization, credential sanitization, and filesystem boundaries enforced across @area44/workflows.
- Untrusted Inputs: Composite action inputs (
runtime,build-command,pathinaction.yml) and workspace configuration files (package.json,.nvmrc,.node-version,.bun-version, lockfiles) are treated as untrusted user input. - Fail-Fast Parsing: Custom
runtimeinputs are parsed and validated byparseEnvironmentInputs()insrc/resolve-environment.tsbefore environment resolution or toolchain setup takes place. Malformed inputs fail fast withINVALID_INPUTorUNSUPPORTED_RUNTIME_OR_PM.
- Custom Build Commands:
src/build-command.tsparses custombuild-commandstrings using a custom tokenizer that respects single quotes, double quotes, and backslash escapes. - No Subshell Invocation: Commands are executed directly as binary names and argument arrays without subshell expansion (avoiding
sh -corbash -c). - Injection Prevention: Shell metacharacters (such as
;,&&,|,$VAR,>) are treated as literal argument values, preventing shell command injection. - Script Runner Sanitization:
src/lint-format.tssanitizes package manager names viasanitizePackageManager()(restricting names to alphanumeric and hyphen characters) before running script hooks.
- Automatic Masking:
sanitizeCommandString()insrc/build-command.tsmasks sensitive tokens before logging or attaching to error contexts:- URLs containing inline authentication credentials (
https://user:pass@host→https://***:***@host). - Sensitive CLI option flags (
--token,--key,--api-key,--pat). - Common access token patterns (GitHub PATs
ghp_...,github_pat_..., npm tokensnpm_..., Slack tokensxox...).
- URLs containing inline authentication credentials (
- Error Context Leak Prevention: Raw
causeobjects attached to exceptions are excluded from attached error contexts to prevent unintentional token or secret exposure.
- Authoritative Source: All TypeScript source code resides in
src/. - Generated Outputs: Files in
dist/are build artifacts bundled vianpm run build(vp pack). Direct manual edits todist/are strictly prohibited. - Automated Verification: Source-to-dist artifact synchronization is verified in CI via
npm run verify:artifacts(src/artifact-integrity.ts). Direct edits todist/trigger build failure.