· via dev.to (home feed)
Woodpecker CI 3.19 patches environment variable injection flaw in default checkout step
Woodpecker CI 3.19 closes a hole that let matrix settings inject environment variables into the default checkout step, and adds better CLI log redaction plus admin-enforced runner labels.

Security fix for the default checkout step
Woodpecker CI, the open-source continuous integration platform, has released version 3.19, and the headline change is a security patch. According to a release summary published on dev.to, drawing on the original report from Hacks.gr, the flaw allowed environment variables from a pipeline's matrix settings to be injected into the default checkout step that clones the repository.
Matrix builds let a single workflow run many times with different parameter combinations. The bug meant those parameters could reach a step that pipeline authors normally never configure themselves: the automatic clone that kicks off each job. Because that step is implicit and shared, values leaking into it from matrix configuration is exactly the behaviour a CI engine should prevent, and version 3.19 closes the gap. The summary does not assign a CVE identifier or severity rating to the issue.
Tighter log redaction and runner governance
Two further changes lean in the same security direction. Sensitive values are now masked more reliably in logs generated when tasks are executed from the command line, lowering the risk of secrets appearing in plain text. Administrators can also require specific labels on the machines that execute tasks, and the platform reports the identity and tags of each machine whenever a task runs. Combined, these let operators pin workloads to trusted or specially provisioned runners rather than whichever agent picks the job up first.
Local execution saw smaller refinements: the path to the program used to execute commands can now be overridden, and a default user account for running tasks has been added, so jobs can be configured to run without administrator privileges.
Reliability and integration fixes
The release addresses several stability problems. Logs could previously disappear when a job finished with skipped steps; that is fixed. Issues around saving settings concurrently have been resolved, and jobs can now be restarted after failures that occur before their settings have been persisted. The platform also no longer crashes when displaying a workflow that contains no steps.
Integration with external services improved as well, with fixes for connecting to Bitbucket Cloud and GitLab and for running Woodpecker on Kubernetes. In local execution, a bug that could halt the machine when a job was cancelled before its first step started has been fixed, some automatic Windows commands have been disabled, and the shutdown of execution machines behaves better.
Under the hood, the project updated its Go toolchain to version 1.27 and refreshed a large portion of its dependencies.
Why it matters
The default checkout step runs in essentially every Woodpecker pipeline, so an injection flaw there is not an edge case — it is a code path that exists in every deployment. CI runners hold source code and credentials, and anything that lets pipeline-controlled values reach an implicit, trusted step widens what a pipeline author can influence beyond what they explicitly configured. The practical takeaway for operators is simple: upgrade to 3.19 rather than waiting for a fuller advisory. The log-redaction and runner-label improvements reinforce the same goal, since secrets leaking into logs and workloads landing on unpinned machines are among the more common ways CI environments get compromised.
- #ci-cd
- #security
- #woodpecker-ci
- #devops
- #open-source