Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Workflows

Question: Can a run script execute text that people outside the repository write? Does a job run pull request code while it has secrets or a write token?

  • Runs: when selected: --rule workflows, --rule security or --rule all · Fails the check by default: no
  • Right on projects JevGate was never tuned on: reviews 1 of 1 (how it is measured)
  • Right on the projects it was tuned on: reviews 0 of 1
  • Looks at: GitHub Actions jobs in .github/workflows
  • Evidence unit: one job with the workflow’s triggers and permissions, and the ${{ }} expressions in its run scripts
  • Acceptable: Untrusted text passed through env variables; pull_request workflows; jobs that run only the base branch’s code
  • Names: security/workflows, workflows, workflows · Version: 2

When a finding is right

A finding says a GitHub Actions job can run text that people outside the repository write, or runs pull request code while it holds secrets or a write token. It is right for ${{ github.event.pull_request.title }} inside a run script, or a pull_request_target job that checks out the pull request’s head and runs it with secrets. It is wrong when outside text reaches only an action’s input rather than a shell, or when the job runs only code from the base branch. Two findings have been labeled on the corpus, one right and one wrong: too few to measure the rule.

Findings it got wrong

Labeled wrong by reading the code, on open-source projects the rules were tuned on.

cookiecutter-django: align-versions.yml

  • Where: .github/workflows/align-versions.yml:16 in cookiecutter/cookiecutter-django at 1ec1d82.
  • Finding (review): Job run places text that people outside the repository write into a run script.
  • Why it was wrong: The job’s only script is uv run ${{ matrix.job.script }}, whose values are the workflow’s own matrix. ${{ github.head_ref }} appears only as the ref: input of actions/checkout, not in a shell, and the job runs on pull_request for the project’s dependency bots or a manual run.
  • Since: not addressed; reported the same way from 0.20.0 through 0.25.0.