aayushxrj / aayushxrj/ai-sast-dast-pipeline-ci-cd

[Security] Security issue in your GitHub CI workflow YAML files

Aperta
#34 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
Lingua principale
Python
Stelle
0
Fork
1
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

Hello maintainers,

I would like to report a potential vulnerability in your GitHub CI workflows.

Affected files:
- aayushxrj/ai-sast-dast-pipeline-ci-cd/.github/workflows/dev-sast-pipeline.yml

Vulnerability:
- In job 'sast', steps 'Run Bandit on changed files (excluding tests/)' and 'Run Semgrep on changed files (excluding tests/)', the list of changed files from an attacker-controlled PR is spliced directly into the run shell via `${{ steps.changed-files.outputs.files }}', allowing command injection through malicious filenames.

Thank you for your time and for maintaining this project.

Guida per i contributori

Nessuna guida per i contributori indicizzata per questo repository

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.