fig. 01 — GHSA-v8mx-hp2q-gw85, the advisory selected below
// advisories
GHSA-v8mx-hp2q-gw85
HIGH
Vela pipelines can use variable substitution combined with insensitive fields like parameters, image and entrypoint to inject secrets into a plugin/image and — by using common substitution string manipulation — can bypass log masking and expose secrets without the use of the commands block. This unexpected behavior primarily impacts secrets restricted by the "no commands" option. This can lead to