Workflows
Question: Can a run script execute text that people outside the repository write? Does a job run pull request code while it has secrets or a write token?
- Runs: when selected:
--rule workflows,--rule securityor--rule all· Fails the check by default: no - Right on projects JevGate was never tuned on: reviews 1 of 1 (how it is measured)
- Right on the projects it was tuned on: reviews 0 of 1
- Looks at: GitHub Actions jobs in .github/workflows
- Evidence unit: one job with the workflow’s triggers and permissions, and the ${{ }} expressions in its run scripts
- Acceptable: Untrusted text passed through env variables; pull_request workflows; jobs that run only the base branch’s code
- Names:
security/workflows,workflows,workflows· Version: 2
When a finding is right
A finding says a GitHub Actions job can run text that people outside the repository write, or runs pull request code while it holds secrets or a write token. It is right for ${{ github.event.pull_request.title }} inside a run script, or a pull_request_target job that checks out the pull request’s head and runs it with secrets. It is wrong when outside text reaches only an action’s input rather than a shell, or when the job runs only code from the base branch. Two findings have been labeled on the corpus, one right and one wrong: too few to measure the rule.
Findings it got wrong
Labeled wrong by reading the code, on open-source projects the rules were tuned on.
cookiecutter-django: align-versions.yml
- Where:
.github/workflows/align-versions.yml:16in cookiecutter/cookiecutter-django at1ec1d82. - Finding (review): Job
runplaces text that people outside the repository write into arunscript. - Why it was wrong: The job’s only script is
uv run ${{ matrix.job.script }}, whose values are the workflow’s own matrix.${{ github.head_ref }}appears only as theref:input ofactions/checkout, not in a shell, and the job runs onpull_requestfor the project’s dependency bots or a manual run. - Since: not addressed; reported the same way from 0.20.0 through 0.25.0.