github / github/codeql

False positive on actions/unpinned-tag for immutable third party action

未關閉
#20,458 3 則留言 6 個 reaction 已指派 0 人 在 GitHub 檢視
false-positive
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

**Description of the false positive**

CodeQL treats e.g. `aws-actions/configure-aws-credentials@v5.0.0` as non-immutable although [it now](https://github.com/aws-actions/configure-aws-credentials#versioning) is.

**Code samples or links to source code**

The following snippet will trigger the `actions/unpinned-tag` rule violation:

```
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v5.0.0
with:
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
aws-region: us-east-1
role-session-name: github-deployment
```

Starting with v5.0.0 this is now the first action from a third party that I've spotted that also got the "Immutable" tag: https://github.com/aws-actions/configure-aws-credentials/releases/tag/v5.0.0

This raises a general question how CodeQL can identify immutable actions.

Right now some organizations are defined as trusted in https://github.com/github/codeql/blob/4f8166a661eb374bf733bd8d155922f9f728f4ca/actions/ql/lib/ext/config/trusted_actions_owner.yml
However, the `aws-actions` org per-se can't be added as not all actions are immutable (yet)

I am not sure if it's enough to add the action repo to https://github.com/github/codeql/blob/203788d4f1913f40d1ba8b2708d8f9c71206b6f4/actions/ql/lib/ext/config/immutable_actions.yml ?

This would still cause a lot of manual effort to keep up to date with the list of growing immutable actions.
I assume this data should be fetched from the GH API in the future to evaluate the immutability status.

貢獻指南

開啟貢獻指南

研究方向

Start by reproducing the actions/unpinned-tag finding with the aws-actions/configure-aws-credentials@v5.0.0 example. Read immutable_actions.yml and trusted_actions_owner.yml to understand the current configuration, then determine how the action’s Immutable status should be recognized without trusting the whole organization. Done means the example no longer produces a false positive and the approach addresses the stated maintenance concern.

由索引模型根據 Issue 內容生成。

評估

技術堆疊
github-actions
領域
ci-cd, security
Issue 類型
缺陷
難度
4/5
預估耗時
3-5 天
活躍度
冷清
描述清晰度
基本清楚
新手友好度
44/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。