github / github/codeql

GHAS-managed workflows reference mutable action versions, incompatible with required SHA-pinning policies

Aberta
#21,732 7 comentários 5 reações 0 responsáveis Ver no GitHub
question
Linguagem predominante
CodeQL
Estrelas
10.1k
Forks
2.1k
Merge médio
2d 15h
PRs com merge (30d)
141

Descrição

## Summary

GitHub Advanced Security (including dynamic analysis and Copilot code review) uses GitHub Actions workflows that reference external actions by mutable labels (e.g. `actions/setup-dotnet@v5`). When an organization enables the recommended policy **“Require actions to be pinned to a full-length commit SHA”**, these workflows fail or remain indefinitely queued.

This puts customers in a position where they must weaken their supply-chain security posture in order to run GitHub’s own security tooling, which should not be required.

## Details

We have an organization with the following Actions policies enabled:

* Require actions to be pinned to a full-length commit SHA
* Allow select actions and reusable workflows (deny by default)

With this posture:

* GitHub Advanced Security **dynamic analysis** fails to run because it references actions such as:
* `actions/setup-dotnet@v5`
* The **Copilot code review** dynamic workflow now fails for the same reason, due to additional external actions referenced by mutable tags

These workflows are **GitHub-managed** and **not user-editable**, so customers cannot remediate the issue by pinning SHAs themselves.

## Expected behavior

GitHub Advanced Security and Copilot security workflows should be compatible with GitHub’s own recommended supply‑chain security controls.

At least one of the following should be true:

* GitHub-managed workflows use **full commit SHAs**, or
* GitHub provides an explicit **first‑party exemption mechanism** that does not require weakening org policy, or
* GitHub publishes **documented, pinned equivalents** for first‑party security workflows

## Actual behavior

* GHAS workflows fail or remain indefinitely queued
* Customers are forced to choose between:
* Enforcing SHA pinning (recommended best practice), or
* Running GitHub’s security tools

There is currently no supported way to do both without introducing a policy exception.

## Impact

* Forces security-conscious customers to weaken their supply-chain controls
* Creates audit and compliance issues (especially for regulated environments)
* Undermines the guidance GitHub itself provides around SHA-pinning
* Affects multiple first‑party security features (dynamic analysis, Copilot code review)

This is not limited to a single action or language ecosystem.

## Reproduction (high level)

1. Enable GHAS dynamic analysis and/or Copilot code review
2. Enable **Require actions to be pinned to a full-length commit SHA**
3. Restrict allowed actions to an allow-list
4. Trigger a PR or default branch run
5. Observe GHAS-managed workflows failing or stuck in `queued`

## Additional context

* Customers cannot edit or fork GHAS-managed workflows
* These are first‑party GitHub security tools
* The workaround today is to relax Actions policies, which contradicts GitHub security guidance

Happy to provide additional diagnostics if needed.

Guia de contribuição

Abrir o guia de contribuição

Direção de pesquisa

Comece pelos workflows de análise dinâmica do GHAS e de revisão de código do Copilot descritos nas etapas de reprodução e, em seguida, verifique o comportamento deles com o pinning de SHA completo e uma política de allow-list habilitada. O trabalho estará concluído quando os workflows gerenciados pelo GitHub forem executados com sucesso sem enfraquecer essas políticas nem exigir que os clientes editem os workflows.

Escrita pelo modelo de indexação a partir do texto da issue.

Avaliação

Stack de tecnologia
github-actions
Domínio
ci-cd, security
Tipo de issue
Bug
Dificuldade
5/5
Tempo estimado
Mais de uma semana
Status de atividade
Pouca atividade
Clareza
Precisa de esclarecimento
Facilidade para iniciantes
25/100

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.