zizmor 1.24.0

Static analysis for GitHub Actions
on:
  pull_request_target: # zizmor: ignore[dangerous-triggers]

name: github_env

permissions: {}

jobs:
  vulnerable:
    name: vulnerable
    runs-on: ubuntu-latest

    steps:
      - name: Passes the title around
        env:
          TITLE: ${{ github.event.pull_request.title }}
        run: |
          message=$(echo "$TITLE" | grep -oP '[{\[][^}\]]+[}\]]' | sed 's/{\|}\|\[\|\]//g')
          echo "message=$message" >> $GITHUB_ENV