Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ jobs:

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@v3
uses: github/codeql-action/init@v4

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

pre-existing: CodeQL actions pinned to a mutable tag (@v4) rather than an immutable SHA

Lines 25, 35, and 49 all reference github/codeql-action/{init,autobuild,analyze}@v4, a mutable tag. A supply-chain attacker who force-pushes the v4 tag to a malicious commit would silently replace this security scanner with arbitrary code running with security-events: write access — the exact permission needed to tamper with SARIF results. SHA pinning (e.g. @<full-sha>) is the standard mitigation. The v3 references also used a mutable tag, so this pattern predates the diff.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: Floating semver tags used instead of pinned SHA digests

All four action references (actions/checkout@v7, codeql-action/init@v4, codeql-action/autobuild@v4, codeql-action/analyze@v4) use mutable floating tags. A force-pushed or compromised tag silently substitutes different code into a step that holds security-events: write permission, enabling manipulation of SARIF results with no visible diff. The v3→v4 bump was a natural moment to pin each action to an immutable SHA digest; it was not taken.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: Security-critical actions pinned to mutable floating tags instead of immutable commit SHAs

All three steps use floating major-version tags (@v4). For ordinary CI actions this is a minor concern, but github/codeql-action is a security-scanning action: a compromised or force-pushed v4 tag could silently substitute code that exfiltrates repository contents under the guise of a legitimate scan. GitHub's own hardening guidance, OSSF Scorecard, and actionlint all recommend SHA-pinned references (e.g. uses: github/codeql-action/init@<full-sha> # v4) for actions in security workflows. The diff actively writes new @v4 references and is the right moment to pin. Concrete risk: a supply-chain compromise of the codeql-action repo could run arbitrary code in the security-scan job with security-events: write access.

with:
config-file: ./.github/codeql/codeql-config.yml

Expand All @@ -32,7 +32,7 @@ jobs:
# Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
# If this step fails, then you should remove it and run the build manually (see below).
- name: Autobuild
uses: github/codeql-action/autobuild@v3
uses: github/codeql-action/autobuild@v4

# ℹ️ Command-line programs to run using the OS shell.
# 📚 https://git.io/JvXDl
Expand All @@ -46,4 +46,4 @@ jobs:
# make release

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v3
uses: github/codeql-action/analyze@v4