False positive in CWE-829 /UntrustedCheckoutMedium.ql

未关闭
#21,823 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
3/5
预计耗时
1-2 天
新手友好度
55/100
Issue 类型
缺陷
描述清晰度
基本清楚
活跃度
冷清
技术栈
github, github-actions
领域
ci-cd, security

调研方向

从 CWE-829 /UntrustedCheckoutMedium.ql 查询开始,检查报告中链接的 triggered workflow 和 called workflow 示例。将查询结果与 pull_request-triggered workflow 的行为以及链接的 code-scanning alert 进行比较。完成的标准是 called workflow 不再被错误地报告为具有特权。

由索引模型根据 Issue 内容生成。

描述

false-positive

Description of the false positive
When there is a workflow that is triggered by a pull_request, this check considers the called workflow to be privileged even though it is not.

Code samples or links to source code

Triggered Workflow: https://raw.githubusercontent.com/llvm/llvm-project/refs/heads/main/.github/workflows/release-binaries-all.yml
Called Workflow: https://raw.githubusercontent.com/llvm/llvm-project/refs/heads/main/.github/workflows/release-binaries.yml

URL to the alert on GitHub code scanning (optional)

https://github.com/llvm/llvm-project/security/code-scanning/1828

主要语言
CodeQL
星标
10.1k
派生
2.1k
平均合并
2 天 11 小时
30 天内合并 PR
129

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

github/codeql 的其他 Issue

查看 github/codeql 的全部 Issue

相似的 Issue

更多 DevOps Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。