[actions] Alternate actions/checkout paths suppress untrusted-checkout alerts
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Aptitud para principiantes
- 68/100
Línea de trabajo
Empieza por ActionsMutableRefCheckout.getPath() y ActionsSHACheckout.getPath() en actions/ql/lib/codeql/actions/security/UntrustedCheckoutQuery.qll; después, compáralos con LocalScriptExecutionRunStep.getPath() en PoisonableSteps.qll. Usa el reproducer enlazado para verificar la discrepancia actual, añade cobertura de regresión para las formas de ruta indicadas y confirma que las consultas Critical y High informan de los casos con rutas alternativas, mientras que el checkout inmutable sigue sin informarse.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Description of the issue
actions/untrusted-checkout/critical does not report a privileged workflow that checks out an untrusted PR into a non-default path: and then executes a script or local action from that checkout. The actions/untrusted-checkout/high fallback is also suppressed, so neither query reports the workflow.
Minimal reproducer
on: pull_request_target
permissions:
contents: write
jobs:
execute:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
with:
repository: ${{ github.event.pull_request.head.repo.full_name }}
ref: ${{ github.event.pull_request.head.sha }}
path: candidate
- run: bash candidate/proof.sh
actions/checkout places path: candidate under $GITHUB_WORKSPACE, so this executes the same checked-out script relationship as a default checkout followed by bash proof.sh.
Reproduction
The complete reproducer is in public fork PR #1.
- Latest-release fork CI: CodeQL Action 4.37.1, CLI 2.26.1,
codeql/actions-queries0.6.31 - Current-main CI: queries compiled directly from
github/codeql@14450f5bf38ea9a3ce2e0e45dcf51c0bbdd01af5
Both successful runs scanned all 11 workflow files and produced the same result matrix:
| Case | Result |
|---|---|
Default checkout followed by bash proof.sh |
actions/untrusted-checkout/critical |
Default checkout followed by uses: ./.github/actions/proof |
actions/untrusted-checkout/critical |
Default checkout with quoted or $GITHUB_WORKSPACE script paths |
actions/untrusted-checkout/critical |
path: candidate, ./candidate, or candidate/ followed by the corresponding script |
no critical or high alert |
path: candidate followed by uses: ./candidate/.github/actions/proof |
no critical or high alert |
| Immutable checkout control | no critical or high alert |
The CI also executed harmless script and composite-action canaries through the tested paths before analysis.
Expected result
The alternate-path cases should be reported by actions/untrusted-checkout/critical, like their default-path controls. A path-representation mismatch should not suppress both the critical query and its high fallback.
Source-level cause
At current main:
ActionsMutableRefCheckout.getPath()andActionsSHACheckout.getPath()return explicit checkout paths verbatim.LocalScriptExecutionRunStep.getPath()and local-action paths are normalized intoGITHUB_WORKSPACE/...form.- The critical query compares those representations with
isSubpath, while the high query suppresses its fallback because the following step is still aPoisonableStep.
Normalizing explicit actions/checkout paths at the checkout model, with regression tests for bare, dot-relative, trailing-slash, and local-action forms, appears to be the smallest fix.
- Lenguaje dominante
- CodeQL
- Estrellas
- 10.1k
- Forks
- 2.1k
- Merge medio
- 2 d 10 h
- PR fusionados (30 d)
- 134
Guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de github/codeql
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
-
C#: cs/simplifiable-boolean-expression false positive on Nullable<bool> compared with a literal Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
-
false-positive
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
-
false-positive
Dificultad 3/5 1-2 días Aptitud para principiantes 68/100
Todos los issues de github/codeql
Issues similares
-
kind/bug needs-triage
Dificultad 1/5 Menos de una hora Aptitud para principiantes 72/100
matrixorigin/matrixone#29223 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
copse-dev/agent-pane#2953 ·
-
bug ci-failure high priority
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
vllm-project/vllm-omni#7972 · 1 comentario ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 90/100
simonw/sqlite-utils#872 ·
-
bug good first issue
Dificultad 1/5 Menos de una hora Aptitud para principiantes 88/100
amponce/archive-movie-browser#166 ·