github / github/codeql

False positive on actions/unpinned-tag for immutable third party action

Aperta
#20,458 3 commenti 6 reazioni 0 assegnatari Vedi su GitHub
false-positive
Lingua principale
CodeQL
Stelle
10.1k
Fork
2.1k
Merge medio
2g 15h
PR unite (30g)
141

Descrizione

**Description of the false positive**

CodeQL treats e.g. `aws-actions/configure-aws-credentials@v5.0.0` as non-immutable although [it now](https://github.com/aws-actions/configure-aws-credentials#versioning) is.

**Code samples or links to source code**

The following snippet will trigger the `actions/unpinned-tag` rule violation:

```
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v5.0.0
with:
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
aws-region: us-east-1
role-session-name: github-deployment
```

Starting with v5.0.0 this is now the first action from a third party that I've spotted that also got the "Immutable" tag: https://github.com/aws-actions/configure-aws-credentials/releases/tag/v5.0.0

This raises a general question how CodeQL can identify immutable actions.

Right now some organizations are defined as trusted in https://github.com/github/codeql/blob/4f8166a661eb374bf733bd8d155922f9f728f4ca/actions/ql/lib/ext/config/trusted_actions_owner.yml
However, the `aws-actions` org per-se can't be added as not all actions are immutable (yet)

I am not sure if it's enough to add the action repo to https://github.com/github/codeql/blob/203788d4f1913f40d1ba8b2708d8f9c71206b6f4/actions/ql/lib/ext/config/immutable_actions.yml ?

This would still cause a lot of manual effort to keep up to date with the list of growing immutable actions.
I assume this data should be fetched from the GH API in the future to evaluate the immutability status.

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Start by reproducing the actions/unpinned-tag finding with the aws-actions/configure-aws-credentials@v5.0.0 example. Read immutable_actions.yml and trusted_actions_owner.yml to understand the current configuration, then determine how the action’s Immutable status should be recognized without trusting the whole organization. Done means the example no longer produces a false positive and the approach addresses the stated maintenance concern.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
github-actions
Ambito
ci-cd, security
Tipo di issue
Bug
Difficoltà
4/5
Tempo stimato
3-5 giorni
Stato di attività
Tranquilla
Chiarezza
Abbastanza chiara
Idoneità per principianti
44/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.