Upgrade actions/checkout and related actions to v7#253
Conversation
Mayhem Automated Code Testing Report❗ 1 Defects Found
Testing details found at https://app.mayhem.security/forallsecure/mcode-action/mayhemit/44 |
|
Semgrep found 10
GitHub Actions step uses a mutable tag or branch reference. Tags and branch names can be silently repointed by the action owner, enabling supply-chain attacks — as seen in the trivy-action and kics-github-action compromises. Pin the reference to a full 40-character commit SHA instead, e.g. |
| steps: | ||
| # X.X.X - Latest version available at: https://github.com/kunalnagarco/action-cve/releases | ||
| - uses: kunalnagarco/action-cve@v1.12.36 | ||
| - uses: kunalnagarco/action-cve@v1.17.3 |
There was a problem hiding this comment.
Semgrep identified an issue in your code:
GitHub Actions step uses mutable version tag v1.17.3 instead of a pinned commit SHA, allowing the action owner to silently redirect your workflow to malicious code via tag reassignment.
More details about this
The step references kunalnagarco/action-cve@v1.17.3 using a version tag (v1.17.3) instead of a pinned commit SHA. Version tags are mutable—the owner can re-tag v1.17.3 to point to different code at any time without any warning or notification to users. This creates a supply-chain attack vector where an attacker could compromise the repository, re-tag an older version to malicious code, and silently inject that code into your workflow on the next run.
Here's how an attack could happen:
- An attacker gains access to the
kunalnagarco/action-cverepository (through compromised credentials or social engineering) - The attacker modifies the code in that repository to include malicious logic (e.g., exfiltrating your
secrets.PERSONAL_ACCESS_TOKENorsecrets.SLACK_WEBHOOK) - The attacker re-tags
v1.17.3to point to their malicious commit instead of the original code - Your workflow runs and pulls the tag, but now it resolves to the attacker's malicious code instead
- The malicious action extracts your secrets and sends them to an attacker-controlled server, or performs other unauthorized actions with your repository permissions
The fix is to replace the version tag with the full 40-character commit SHA (e.g., uses: kunalnagarco/action-cve@<commit-sha>) so the action always runs the exact code you've audited, regardless of any tag changes.
To resolve this comment:
✨ Commit fix suggestion
| - uses: kunalnagarco/action-cve@v1.17.3 | |
| # TODO: Replace the placeholder below with the exact 40-character commit SHA currently pointed to by the upstream v1.17.3 tag in kunalnagarco/action-cve. | |
| - uses: kunalnagarco/action-cve@<full-40-character-commit-sha> # v1.17.3 |
View step-by-step instructions
-
Replace the mutable action tag with a full 40-character commit SHA in the
usesline. Changekunalnagarco/action-cve@v1.17.3tokunalnagarco/action-cve@<full-40-character-commit-sha>. -
Keep the current version visible by adding the tag as a comment after the SHA, for example:
uses: kunalnagarco/action-cve@<full-40-character-commit-sha> # v1.17.3. -
Get the correct SHA from the action's
v1.17.3release or tag in thekunalnagarco/action-cverepository, and use the commit that the tag currently points to. Pinning to a commit SHA prevents the action owner from silently changing what code runs later. -
Leave the
with:values unchanged unless the pinned commit's release notes say the inputs changed.
💬 Ignore this finding
Reply with Semgrep commands to ignore this finding.
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by github-actions-mutable-action-tag.
You can view more details about this finding in the Semgrep AppSec Platform.
There was a problem hiding this comment.
Agree on this one.
| - uses: kunalnagarco/action-cve@v1.17.3 | |
| - uses: kunalnagarco/action-cve@97cf2131ab6fc1c9892b431608fa3c686805a157 # v1.17.3 |
d-dot-one
left a comment
There was a problem hiding this comment.
Feel free to close all my comments if we are not pinning to a SHA (but we should be) :)
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | ||
| steps: | ||
| - uses: actions/checkout@v4 | ||
| - uses: actions/checkout@v7 |
There was a problem hiding this comment.
All of these should be pinned to a SHA, not a tag. Tags are not guaranteed to be immutable.
| - uses: actions/checkout@v7 | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 |
| runs-on: ubuntu-latest | ||
| steps: | ||
| - uses: actions/checkout@v4 | ||
| - uses: actions/checkout@v7 |
There was a problem hiding this comment.
here too:
| - uses: actions/checkout@v7 | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 |
| steps: | ||
| # X.X.X - Latest version available at: https://github.com/kunalnagarco/action-cve/releases | ||
| - uses: kunalnagarco/action-cve@v1.12.36 | ||
| - uses: kunalnagarco/action-cve@v1.17.3 |
There was a problem hiding this comment.
Agree on this one.
| - uses: kunalnagarco/action-cve@v1.17.3 | |
| - uses: kunalnagarco/action-cve@97cf2131ab6fc1c9892b431608fa3c686805a157 # v1.17.3 |
|
|
||
| - name: Upload SARIF file(s) | ||
| uses: github/codeql-action/upload-sarif@v3 | ||
| uses: github/codeql-action/upload-sarif@v4 |
There was a problem hiding this comment.
This doesn't have a proper release outside of the bundle, so giving this one a pass
| runs-on: ubuntu-latest | ||
| steps: | ||
| - uses: actions/checkout@v4 | ||
| - uses: actions/checkout@v7 |
There was a problem hiding this comment.
here too:
| - uses: actions/checkout@v7 | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 |
|
|
||
| - name: Archive Coverage report | ||
| uses: actions/upload-artifact@v4 | ||
| uses: actions/upload-artifact@v7 |
There was a problem hiding this comment.
| uses: actions/upload-artifact@v7 | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 |
|
|
||
| - name: Archive JUnit results | ||
| uses: actions/upload-artifact@v4 | ||
| uses: actions/upload-artifact@v7 |
There was a problem hiding this comment.
| uses: actions/upload-artifact@v7 | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 |
| runs-on: ubuntu-latest | ||
| steps: | ||
| - uses: actions/checkout@v4 | ||
| - uses: actions/checkout@v7 |
There was a problem hiding this comment.
| - uses: actions/checkout@v7 | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 |
| runs-on: ubuntu-latest | ||
| steps: | ||
| - uses: actions/checkout@v4 | ||
| - uses: actions/checkout@v7 |
There was a problem hiding this comment.
| - uses: actions/checkout@v7 | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 |
| runs-on: ubuntu-latest | ||
| steps: | ||
| - uses: actions/checkout@v4 | ||
| - uses: actions/checkout@v7 |
There was a problem hiding this comment.
| - uses: actions/checkout@v7 | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 |
No description provided.