Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/coverage.yml
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,6 @@ jobs:
run: grcov . -s . --binary-path ./target/debug/ -t lcov --branch --ignore-not-existing -o ./target/debug/coverage/

- name: Upload to codecov.io
uses: codecov/codecov-action@v4
uses: codecov/codecov-action@v7

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Semgrep identified an issue in your code:

The coverage job executes codecov/codecov-action@v7, a mutable tag that can be silently repointed to attacker-controlled code. A compromised action could read repository data and CI credentials from the runner and exfiltrate them.

More details about this

The check job runs codecov/codecov-action@v7 in the Upload to codecov.io step. Because v7 is a mutable tag, the action owner—or an attacker who compromises that repository—could repoint it after this workflow is reviewed, causing future runs to execute attacker-controlled code on ubuntu-latest.

A plausible attack would be:

  1. An attacker gains control of the codecov/codecov-action repository or its v7 tag and changes the action code.
  2. A normal push triggers the check job, which runs the repointed action after the profiling tests and grcov create target/debug/coverage/lcov.
  3. The malicious action reads target/debug/coverage/lcov, repository files, and any credentials or tokens available to the job, then sends them to an attacker-controlled server—for example, by issuing an outbound request from the runner.
  4. The attacker can use any exposed token or credential to access the repository, alter CI results, or pivot into connected services. The same risk already applies to the other mutable action references in this workflow, such as actions/checkout@v3, dtolnay/rust-toolchain@nightly, and Swatinem/rust-cache@v2.

To resolve this comment:

✨ Commit fix suggestion
  1. Replace the mutable tag with the full 40-character commit SHA for the intended codecov/codecov-action release:
    uses: codecov/codecov-action@<40-character-commit-SHA>
  2. Verify that the SHA comes from the official codecov/codecov-action repository and corresponds to the version currently intended by @v7.
  3. Keep the existing with.files configuration unchanged. Pinning the SHA prevents the action reference from silently changing if the tag is moved.
💬 Ignore this finding

Reply with Semgrep commands to ignore this finding.

  • /fp <comment> for false positive
  • /ar <comment> for acceptable risk
  • /other <comment> for all other reasons

Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by github-actions-mutable-action-tag.

You can view more details about this finding in the Semgrep AppSec Platform.

with:
files: target/debug/coverage/lcov
Loading