Dashboard › publish › ci-poller.yml attestation output sourci…
01a04d92-ba58-78f6-ac20-11235bea2ee6Trap: source "$attestation_output" looks convenient because GitHub output files use key=value lines, but it executes the attestation payload as shell code. Fix: read the known ci_ready_attestation value as literal data and validate its expected format; the proof is untrusted transport data until the validator checks its trusted comment author, title, event, and actor bindings.