T08 · Insecure Dependencies
- Location
references/details.md:271- Finding
Unpinned Package Retrieval and Execution in CI
- Content
View full analysis
Vulnerability Details
File Location:
references/details.md, lines 271–276
Vulnerability Type: Unpinned third-party package execution
Risk Level: MediumVulnerable Code:
yaml security: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - name: Security Scan run: npx audit-ci --highTechnical Analysis
The CI example invokes
npx audit-ci --highwithout showing thataudit-ciis installed from an exact, reviewed version recorded in a committed lockfile. If the package is unavailable locally,npxmay retrieve the current package release from the configured npm registry and execute it immediately.This makes the effective code executed by the workflow mutable after the Skill has been reviewed. The resulting supply-chain risk includes package-registry compromise, maintainer-account compromise, or an unexpectedly unsafe future release. The example also references
actions/checkout@v4by a moving major-version tag rather than an immutable reviewed commit SHA, which provides weaker integrity guarantees.Attack Path
- A user copies the documented workflow into a repository.
- The workflow runs in response to a push or pull request.
- The security job invokes
npx audit-ci --high. - If
audit-ciis not installed locally,npxresolves and downloads it from the configured registry. - A compromised or unsafe resolved release executes with the permissions of the CI runner.
- The package can read checked-out repository content, inspect environment data and credentials exposed to that job, alter workspace files, or influence subsequent build outputs.
Successful exploitation depends on compromise or malicious modification of the resolved dependency or its distribution channel.
Impact Assessment
Arbitrary package code can execute with CI-runner privileges. The accessible scope may include:
- Checked-out source code and repository metadata
- Environment variables available to the security ...[truncated 334 chars]
- Remediation
View remediation
Remediation Suggestions
- Add
audit-citodevDependenciesusing an exact reviewed version rather than relying on runtime package resolution. - Commit the package lockfile and install dependencies with
npm ci. - Prevent
npxfrom downloading missing packages:
yaml - name: Install run: npm ci - name: Security Scan run: npx --no-install audit-ci --high- Alternatively, invoke a lockfile-controlled npm script:
json { "scripts": { "security:audit": "audit-ci --high" } }yaml - name: Security Scan run: npm run security:audit- Pin GitHub Actions to reviewed immutable commit SHAs instead of moving tags.
- Configure minimal workflow permissions, for example
contents: read, and grant no write permissions unless explicitly required. - Avoid exposing deployment credentials or unrelated secrets to dependency-scanning jobs.
- Use dependency update automation with mandatory review and CI validation for version changes.
- Add
