fig. 01 — GHSA-4jhj-3gv3-c3gr, the advisory selected below
// advisories
GHSA-4jhj-3gv3-c3gr
HIGH
Vela pipelines can use variable substitution combined with insensitive fields like parameters, image and entrypoint to inject secrets into a plugin/image and — by using common substitution string manipulation — can bypass log masking and expose secrets without the use of the commands block. This unexpected behavior primarily impacts secrets restricted by the "no commands" option. This can lead to