github / github/codeql

False positive on actions/unpinned-tag for immutable third party action

Abierto
#20,458 3 comentarios 6 reacciones 0 asignados Ver en GitHub
false-positive
Lenguaje dominante
CodeQL
Estrellas
10.1k
Forks
2.1k
Merge medio
2 d 15 h
PR fusionados (30 d)
141

Descripción

**Description of the false positive**

CodeQL treats e.g. `aws-actions/configure-aws-credentials@v5.0.0` as non-immutable although [it now](https://github.com/aws-actions/configure-aws-credentials#versioning) is.

**Code samples or links to source code**

The following snippet will trigger the `actions/unpinned-tag` rule violation:

```
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v5.0.0
with:
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
aws-region: us-east-1
role-session-name: github-deployment
```

Starting with v5.0.0 this is now the first action from a third party that I've spotted that also got the "Immutable" tag: https://github.com/aws-actions/configure-aws-credentials/releases/tag/v5.0.0

This raises a general question how CodeQL can identify immutable actions.

Right now some organizations are defined as trusted in https://github.com/github/codeql/blob/4f8166a661eb374bf733bd8d155922f9f728f4ca/actions/ql/lib/ext/config/trusted_actions_owner.yml
However, the `aws-actions` org per-se can't be added as not all actions are immutable (yet)

I am not sure if it's enough to add the action repo to https://github.com/github/codeql/blob/203788d4f1913f40d1ba8b2708d8f9c71206b6f4/actions/ql/lib/ext/config/immutable_actions.yml ?

This would still cause a lot of manual effort to keep up to date with the list of growing immutable actions.
I assume this data should be fetched from the GH API in the future to evaluate the immutability status.

Guía de contribución

Abrir la guía de contribución

Línea de trabajo

Start by reproducing the actions/unpinned-tag finding with the aws-actions/configure-aws-credentials@v5.0.0 example. Read immutable_actions.yml and trusted_actions_owner.yml to understand the current configuration, then determine how the action’s Immutable status should be recognized without trusting the whole organization. Done means the example no longer produces a false positive and the approach addresses the stated maintenance concern.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
github-actions
Área
ci-cd, security
Tipo de issue
Error
Dificultad
4/5
Tiempo estimado
3-5 días
Estado de actividad
Tranquilo
Claridad
Bastante claro
Aptitud para principiantes
44/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.