aayushxrj / aayushxrj/ai-sast-dast-pipeline-ci-cd
[Security] Security issue in your GitHub CI workflow YAML files
未關閉
- 主要語言
- Python
- 星號
- 0
- 分支
- 1
- PR 合併指標
- 30 天內沒有已合併 PR
描述
Hello maintainers,
I would like to report a potential vulnerability in your GitHub CI workflows.
Affected files:
- aayushxrj/ai-sast-dast-pipeline-ci-cd/.github/workflows/dev-sast-pipeline.yml
Vulnerability:
- In job 'sast', steps 'Run Bandit on changed files (excluding tests/)' and 'Run Semgrep on changed files (excluding tests/)', the list of changed files from an attacker-controlled PR is spliced directly into the run shell via `${{ steps.changed-files.outputs.files }}', allowing command injection through malicious filenames.
Thank you for your time and for maintaining this project.
貢獻指南
這個儲存庫沒有索引到貢獻指南
評估
這個 Issue 還沒有評估資料。