Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Semgrep identified an issue in your code:
The workflow runs
actions/add-to-projectfrom mutable tagv2.0.0, so a tag change could execute attacker-controlled code withADD_TO_PROJECT_PAT.More details about this
actions/add-to-project@v2.0.0is a mutable release tag, not an immutable commit reference. The action owner—or an attacker who compromises that repository—could movev2.0.0to a malicious commit without changing this workflow.A plausible attack would be:
v2.0.0tag inactions/add-to-projectto code that still appears to add issues to the project but also reads${{ secrets.ADD_TO_PROJECT_PAT }}.add-to-projectjob through theissuesworkflow event.github-tokenvalue supplied fromsecrets.ADD_TO_PROJECT_PAT.To resolve this comment:
🔧 No guidance has been designated for this issue. Fix according to your organization's approved methods.
💬 Ignore this finding
Reply with Semgrep commands to ignore this finding.
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasonsAlternatively, triage in Semgrep AppSec Platform to ignore the finding created by github-actions-mutable-action-tag.
You can view more details about this finding in the Semgrep AppSec Platform.