github / github/codeql

Organization owned immutable actions raise warning about unpinned 3rd party actions tag

オープン 初心者向け
#21,076 コメント 3 件 リアクション 3 件 担当者 0 名 GitHub で見る
false-positive
主要言語
CodeQL
スター
10.1k
フォーク
2.1k
平均マージ
2日 15時間
マージ済み PR(30日)
141

説明

This CodeQL warning is great, but its language specifically says 3rd party actions, but my actions are getting warnings even when they're immutable and owned by my organization.

https://github.com/github/codeql/blob/28b6aa8616a393ebb45186e3ba4df004a0f3ef4e/actions/ql/src/Security/CWE-829/UnpinnedActionsTag.ql#L1-L12

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

Start with actions/ql/src/Security/CWE-829/UnpinnedActionsTag.ql, especially lines 1-12 linked in the issue, and inspect how the warning describes organization-owned immutable actions. Reproduce or examine that case, then verify that the warning wording and behavior accurately match the affected actions.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
github-actions
領域
security
issue の種類
バグ
難易度
2/5
見積もり時間
1〜3時間
活発さ
活発
明瞭さ
おおむね明確
初心者へのやさしさ
70/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。