fix(ci): 修复提交信息含 ${{ }} 字样导致 pre-check 崩溃
Deploy to Production / pre-check (push) Successful in 2m35s
Deploy to Production / build (push) Successful in 7m53s
Deploy to Production / deploy-edgeone (push) Successful in 3m52s
Deploy to Production / deploy-upyun (push) Successful in 5s
Deploy to Production / finalize (push) Successful in 30s
Deploy to Production / notify-failure (push) Skipped

根因:pre-check 的 Validate commit 步骤把 commit message 直接插值进 shell 脚本:

    COMMIT_MESSAGE="${{ github.event.head_commit.message }}"

多行提交信息会撑破脚本;若正文里出现 ${{ ... }} 之类字样(例如上一次提交
正文中的 ${{ gitea.* }}),bash 会把它当变量展开并报 "bad substitution",
exit 1 → pre-check failure → build 被 skip。

实证(Gitea task 35 日志):
    /var/run/act/workflow/commit-check: line 20: perf(ci): 兼容 GitHub Actions...
    : bad substitution
    ❌ Failure - Main Validate commit (only for push events)

修复:改用 step 级 env: 传值(COMMIT_AUTHOR / COMMIT_MESSAGE),
commit message 不再进入脚本文本。GitHub Actions 与 Gitea Actions
行为一致,两边都安全,同时消除命令注入面。

本次提交正文刻意保留了 ${{ gitea.* }} 字样,作为该修复的回归验证。
This commit is contained in:
zqlit committed 2026-10-01 12:37:22 +08:00
1 parent 92326fff38
commit e1f0b49754
1 file changed
+6 -3
+6 -3
View File
@@ -50,10 +50,13 @@ jobs:
- name: Validate commit (only for push events)
if: github.event_name == 'push'
id: commit-check
# 注意:commit message 是用户可控的多行文本,必须经 env 传入。
# 直接写 ${{ github.event.head_commit.message }} 会把内容展开进脚本,
# 多行信息或含 $ / ` 的字符会导致 "bad substitution" 甚至命令注入。
env:
COMMIT_AUTHOR: ${{ github.event.head_commit.author.name }}
COMMIT_MESSAGE: ${{ github.event.head_commit.message }}
run: |
COMMIT_AUTHOR="${{ github.event.head_commit.author.name }}"
COMMIT_MESSAGE="${{ github.event.head_commit.message }}"
echo "📝 提交作者: $COMMIT_AUTHOR"
echo "📄 提交信息: $COMMIT_MESSAGE"