Unpinned floating tags (e.g. `v4`) on immutable Actions are not flagged by `actions/unpinned-tag`

Đang mở
#22,414 1 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức phù hợp với người mới
55/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Sôi nổi
Lĩnh vực
security

Hướng nghiên cứu

Đọc actions/ql/src/Security/CWE-829/UnpinnedActionsTag.ql và actions/ql/lib/codeql/actions/security/UseOfUnversionedImmutableAction.qll, bắt đầu với isImmutableAction và predicate SemVer hiện có. Được coi là hoàn tất khi các tag vX.Y.Z đầy đủ và SHA đầy đủ vẫn được miễn, trong khi các tham chiếu trôi nổi như vX và vX.Y bị báo cáo, kèm theo ghi chú thay đổi bắt buộc.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Description of the issue

The actions/unpinned-tag query (actions/ql/src/Security/CWE-829/UnpinnedActionsTag.ql) exempts any Action on the immutable-actions allow list from the unpinned-tag warning, regardless of the ref used. The exclusion is version-independent:

not exists(UsesStep step | uses = step and isImmutableAction(step, nwo))

and isImmutableAction (actions/ql/lib/codeql/actions/security/UseOfUnversionedImmutableAction.qll) only checks membership in immutableActionsDataModel(nwo); it never inspects the version.

Why this is a gap

GitHub's immutability guarantee only applies to fully-expanded SemVer release tags (vX.Y.Z) and full commit SHAs. Floating tags such as v4, v4.0 and main remain mutable: maintainers move them to the latest matching release, so they can change under a consumer exactly like any other tag. See Using immutable releases and tags to manage your action's releases.

As a result, a reference like actions/checkout@v2 is flagged by neither query:

  • UnpinnedActionsTag skips it because actions/checkout is on the immutable list.
  • UnversionedImmutableAction skips it because its isSemVer predicate accepts a bare major tag like v2.

So a genuinely mutable floating tag on an immutable Action goes unwarned.

Suggested direction

Narrow the exemption so an immutable Action is only exempt when pinned to a full vX.Y.Z (or a SHA), for example:

not (isImmutableAction(step, nwo) and isFullSemVer(version))

with an isFullSemVer stricter than the current isSemVer (which also matches floating vX and vX.Y). This would need care because the immutable-action model is shared with the experimental UnversionedImmutableAction query, and it would increase alert volume for consumers pinning immutable Actions to floating major tags, so it deserves its own change note and review.

Filed as a follow-up to #22409 (which is scoped to the trusted-owner allow list and does not address this).

Ngôn ngữ chính
CodeQL
Star
10.1k
Fork
2.1k
Merge trung bình
2 ngày 10 giờ
Pull request đã merge (30 ngày)
134

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của github/codeql

Tất cả issue của github/codeql

Issue tương tự

Thêm issue về Security

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.