aayushxrj / aayushxrj/ai-sast-dast-pipeline-ci-cd

[Security] Security issue in your GitHub CI workflow YAML files

未關閉
#34 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
Python
星號
0
分支
1
PR 合併指標
30 天內沒有已合併 PR

描述

Hello maintainers,

I would like to report a potential vulnerability in your GitHub CI workflows.

Affected files:
- aayushxrj/ai-sast-dast-pipeline-ci-cd/.github/workflows/dev-sast-pipeline.yml

Vulnerability:
- In job 'sast', steps 'Run Bandit on changed files (excluding tests/)' and 'Run Semgrep on changed files (excluding tests/)', the list of changed files from an attacker-controlled PR is spliced directly into the run shell via `${{ steps.changed-files.outputs.files }}', allowing command injection through malicious filenames.

Thank you for your time and for maintaining this project.

貢獻指南

這個儲存庫沒有索引到貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。