aayushxrj / aayushxrj/ai-sast-dast-pipeline-ci-cd
[Security] Security issue in your GitHub CI workflow YAML files
- Dominant language
- Python
- Stars
- 0
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Description
Hello maintainers,
I would like to report a potential vulnerability in your GitHub CI workflows.
Affected files:
- aayushxrj/ai-sast-dast-pipeline-ci-cd/.github/workflows/dev-sast-pipeline.yml
Vulnerability:
- In job 'sast', steps 'Run Bandit on changed files (excluding tests/)' and 'Run Semgrep on changed files (excluding tests/)', the list of changed files from an attacker-controlled PR is spliced directly into the run shell via `${{ steps.changed-files.outputs.files }}', allowing command injection through malicious filenames.
Thank you for your time and for maintaining this project.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.