False positive on actions/unpinned-tag for immutable third party action
- 主要語言
- CodeQL
- 星號
- 10.1k
- 分支
- 2.1k
- 平均合併
- 2 天 15 小時
- 30 天內合併 PR
- 141
描述
**Description of the false positive**
CodeQL treats e.g. `aws-actions/configure-aws-credentials@v5.0.0` as non-immutable although [it now](https://github.com/aws-actions/configure-aws-credentials#versioning) is.
**Code samples or links to source code**
The following snippet will trigger the `actions/unpinned-tag` rule violation:
```
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v5.0.0
with:
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
aws-region: us-east-1
role-session-name: github-deployment
```
Starting with v5.0.0 this is now the first action from a third party that I've spotted that also got the "Immutable" tag: https://github.com/aws-actions/configure-aws-credentials/releases/tag/v5.0.0
This raises a general question how CodeQL can identify immutable actions.
Right now some organizations are defined as trusted in https://github.com/github/codeql/blob/4f8166a661eb374bf733bd8d155922f9f728f4ca/actions/ql/lib/ext/config/trusted_actions_owner.yml
However, the `aws-actions` org per-se can't be added as not all actions are immutable (yet)
I am not sure if it's enough to add the action repo to https://github.com/github/codeql/blob/203788d4f1913f40d1ba8b2708d8f9c71206b6f4/actions/ql/lib/ext/config/immutable_actions.yml ?
This would still cause a lot of manual effort to keep up to date with the list of growing immutable actions.
I assume this data should be fetched from the GH API in the future to evaluate the immutability status.
貢獻指南
研究方向
Start by reproducing the actions/unpinned-tag finding with the aws-actions/configure-aws-credentials@v5.0.0 example. Read immutable_actions.yml and trusted_actions_owner.yml to understand the current configuration, then determine how the action’s Immutable status should be recognized without trusting the whole organization. Done means the example no longer produces a false positive and the approach addresses the stated maintenance concern.
由索引模型根據 Issue 內容生成。
評估
- 技術堆疊
- github-actions
- 領域
- ci-cd, security
- Issue 類型
- 缺陷
- 難度
- 4/5
- 預估耗時
- 3-5 天
- 活躍度
- 冷清
- 描述清晰度
- 基本清楚
- 新手友好度
- 44/100