CI hardening: testdriver.yml uses testdriverai/action@main (mutable branch) in a job holding DASHCAM_API + GITHUB_TOKEN
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 1/5
- Thời gian dự kiến
- Dưới một giờ
- Mức phù hợp với người mới
- 85/100
Hướng nghiên cứu
Mở .github/workflows/testdriver.yml và kiểm tra tham chiếu testdriverai/action@main trong job run_testdriver. Tìm SHA commit đầy đủ hiện tại của action đó, thay thế ref có thể thay đổi bằng SHA và một chú thích giải thích, sau đó xác thực rằng workflow không yêu cầu thay đổi nào khác.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Summary
.github/workflows/testdriver.yml pins a third-party action to a mutable branch — uses: testdriverai/action@main — inside a job that holds real secrets. I wanted to flag it as a small supply-chain hardening opportunity, and I'm happy to open the one-line fix if that's welcome.
I know this is a solo-maintained project with a discuss-first process, so please treat this as a heads-up rather than a demand on your time — no worries at all if it's not a priority.
What I observed (facts, at commit c99022c)
In testdriver.yml, the run_testdriver job:
- triggers on
workflow_run(line 3–4) — which runs from the default branch with access to repo secrets; - runs
uses: testdriverai/action@main(line 50).testdriverai/actionis a third-party action (ownertestdriverai, notwavetermdev/actions;default_branch: main), so@mainresolves to whatever that branch's HEAD points at, at run time; - in that same step passes
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}(line 54) andkey: ${{ secrets.DASHCAM_API }}(line 56), and embeds theGITHUB_TOKENin anAuthorizationheader (line 59). Job permissions arecontents: read+statuses: write.
Every other third-party action in the file is pinned to a version tag (e.g. mlugg/setup-zig@v2, nick-fields/retry@v4, softprops/action-gh-release@v2) — testdriverai/action@main is the only one on a moving branch.
Why I think it's worth a look (my inference)
If that upstream branch were ever repointed to malicious code — the class of thing that happened with tj-actions/changed-files in 2025 — it would execute in a job that can read DASHCAM_API and use the GITHUB_TOKEN. Pinning to a full commit SHA closes that window while still letting you bump it deliberately. I also noticed dependabot.yml enables the github-actions ecosystem, but Dependabot updates tags/SHAs and can't rewrite a @main branch ref, so this particular pin isn't covered by your existing tooling.
Suggested fix
Pin to the current commit SHA with a comment, e.g.:
- uses: testdriverai/action@<full-40-char-sha> # main as of <date>
I checked open and closed issues/PRs and didn't find an existing one for this. If you'd like, I'm glad to open a tiny PR with the SHA pin (I'd sign the CLA first) — or feel free to just make the one-line change yourself, whichever is less overhead for you.
Disclosure: I used an AI tool to help spot this and draft the report; I verified every line against the workflow file at the commit above myself and take responsibility for it.
- Ngôn ngữ chính
- Go
- Star
- 22.4k
- Fork
- 1.2k
- Merge trung bình
- 3 ngày 13 giờ
- Pull request đã merge (30 ngày)
- 14
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của wavetermdev/waveterm
-
pwsh: encodeEnvVarsForPowerShell rejects Windows-standard env var names like ProgramFiles(x86), breaking wsh token on every pwsh blockCó thể đã có người làm @vortsghost2025 đã nhận 28 ngày trước. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
wavetermdev/waveterm#3481 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
wavetermdev/waveterm#3435 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
enhancement triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
wavetermdev/waveterm#3431 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
[Bug]: web blocks become unresponsive when switching focus between two of themCó thể đã có người làm @jameswolensky đã nhận 86 ngày trước. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 86/100
wavetermdev/waveterm#3428 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Feature request: emit a distinct CSI-u sequence for Ctrl+Enter in terminal blocksCó thể đã có người làm @Jason-Shen2 đã nhận 96 ngày trước. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
wavetermdev/waveterm#3355 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của wavetermdev/waveterm
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 86/100
war-and-code/dircue#200 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
actor/human kind/bug priority/important-soon triage-accepted
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 66/100
kelos-dev/kelos#1804 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
Maintainer thường phản hồi trong vòng 1 ngày
-
`date` → `date-time` (and `time` → `date-time`) is classified as a widening, but a date is not a valid date-timeCó thể đã có người làm @reuvenharrison đã nhận hôm nay. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
Maintainer thường phản hồi trong vòng 1 ngày
-
fix: invalid GPU spec in SparkApplication is silently ignoredCó thể đã có người làm @pratik-naik003 đã nhận hôm nay. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
kubeflow/spark-operator#3223 ·
Maintainer thường phản hồi trong vòng 5 ngày