From 37ac53ed4a4e60a5fb591e7696f56ebb10edc8dd Mon Sep 17 00:00:00 2001 From: Daniel <57051444+daniel-lxs@users.noreply.github.com> Date: Thu, 6 Nov 2025 16:40:03 -0500 Subject: [PATCH] fix: prevent shell injection in pre-push hook environment loading (#9059) --- .husky/pre-push | 17 ++++++++++------- 1 file changed, 10 insertions(+), 7 deletions(-) diff --git a/.husky/pre-push b/.husky/pre-push index 9e41e80cf8..4cf91d9580 100644 --- a/.husky/pre-push +++ b/.husky/pre-push @@ -18,14 +18,17 @@ fi $pnpm_cmd run check-types -# Load .env.local if it exists +# Use dotenvx to securely load .env.local and run commands that depend on it if [ -f ".env.local" ]; then - export $(grep -v '^#' .env.local | xargs) -fi - -# Run tests if RUN_TESTS_ON_PUSH is set to true -if [ "$RUN_TESTS_ON_PUSH" = "true" ]; then - $pnpm_cmd run test + # Check if RUN_TESTS_ON_PUSH is set to true and run tests with dotenvx + if npx dotenvx get RUN_TESTS_ON_PUSH -f .env.local 2>/dev/null | grep -q "^true$"; then + npx dotenvx run -f .env.local -- $pnpm_cmd run test + fi +else + # Fallback: run tests if RUN_TESTS_ON_PUSH is set in regular environment + if [ "$RUN_TESTS_ON_PUSH" = "true" ]; then + $pnpm_cmd run test + fi fi # Check for new changesets.