Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/new_issue.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ jobs:
name: Add issue to project
runs-on: ubuntu-latest
steps:
- uses: actions/add-to-project@v0.5.0
- uses: actions/add-to-project@v2.0.0

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Semgrep identified an issue in your code:

The workflow runs actions/add-to-project from mutable tag v2.0.0, so a tag change could execute attacker-controlled code with ADD_TO_PROJECT_PAT.

More details about this

actions/add-to-project@v2.0.0 is a mutable release tag, not an immutable commit reference. The action owner—or an attacker who compromises that repository—could move v2.0.0 to a malicious commit without changing this workflow.

A plausible attack would be:

  1. An attacker repoints the v2.0.0 tag in actions/add-to-project to code that still appears to add issues to the project but also reads ${{ secrets.ADD_TO_PROJECT_PAT }}.
  2. Someone opens an issue, triggering the add-to-project job through the issues workflow event.
  3. The runner executes the newly tagged action with the github-token value supplied from secrets.ADD_TO_PROJECT_PAT.
  4. The malicious action sends that token to an attacker-controlled endpoint, allowing the attacker to use the PAT's GitHub permissions to access or modify project and repository data.

To resolve this comment:

🔧 No guidance has been designated for this issue. Fix according to your organization's approved methods.

💬 Ignore this finding

Reply with Semgrep commands to ignore this finding.

  • /fp <comment> for false positive
  • /ar <comment> for acceptable risk
  • /other <comment> for all other reasons

Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by github-actions-mutable-action-tag.

You can view more details about this finding in the Semgrep AppSec Platform.

with:
project-url: https://github.com/orgs/openmls/projects/9
github-token: ${{ secrets.ADD_TO_PROJECT_PAT }}
Loading