False positive: Workflow does not contain permissions
- 主要語言
- CodeQL
- 星號
- 10.1k
- 分支
- 2.1k
- 平均合併
- 2 天 15 小時
- 30 天內合併 PR
- 141
描述
**Description of the false positive**
We get a lot of `Workflow does not contain permissions` alerts.
It's description states
> If a GitHub Actions job or workflow has no explicit permissions set, then the repository permissions are used. Repositories created under organizations inherit the organization permissions. The organizations or repositories created before February 2023 have the default permissions set to read-write. Often these permissions do not adhere to the principle of least privilege and can be reduced to read-only, leaving the write permission only to a specific types as issues: write or pull-requests: write.
While our org was created before February 2023, the default permission on the org is set to read contents and packages only, and in the repository I can't even change the setting.
**Code samples or links to source code**
https://github.com/intility/templates/blob/8653a13809c06c5046e57cb689d8479726380414/.github/workflows/build-react.yml#L13-L36
**URL to the alert on GitHub code scanning (optional)**
https://github.com/intility/templates/security/code-scanning/4
貢獻指南
研究方向
Start with the linked workflow at .github/workflows/build-react.yml, lines 13-36, and compare its permissions with the reported code-scanning alert. Determine whether the alert is a false positive given the organization and repository defaults, then verify that the alert behavior or query outcome matches the documented permissions model.
由索引模型根據 Issue 內容生成。
評估
- 技術堆疊
- github-actions
- 領域
- ci-cd, security
- Issue 類型
- 缺陷
- 難度
- 3/5
- 預估耗時
- 1-2 天
- 活躍度
- 停滯
- 描述清晰度
- 基本清楚
- 新手友好度
- 35/100