zizmor 1.23.0

Static analysis for GitHub Actions
on:
  pull_request_target: # zizmor: ignore[dangerous-triggers]

permissions: {}

name: github-path

jobs:
  vulnerable:
    name: vulnerable
    runs-on: ubuntu-latest

    steps:
      - name: Passes the title around
        env:
          TITLE: ${{ github.event.pull_request.title }}
        run: |
          message=$(echo "$TITLE" | grep -oP '[{\[][^}\]]+[}\]]' | sed 's/{\|}\|\[\|\]//g')
          echo "$message" >> $GITHUB_PATH