T08 · Insecure Dependencies
- Location
references/details.md:276- Finding
Unpinned Third-Party Package Execution in CI Example
- Content
View full analysis
Vulnerability Details
File Location:
references/details.md, line 276
Vulnerability Type: Unpinned package execution throughnpx
Risk Level: MediumVulnerable Code Snippet:
yaml security: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - name: Security Scan run: npx audit-ci --highTechnical Analysis
The documented CI workflow executes
audit-cithroughnpxwithout specifying an exact package version. The package is also not shown as a lockfile-pinned project dependency. If the package is unavailable locally,npxmay resolve, download, and immediately execute a package selected from the configured npm registry.This creates mutable CI behavior: the code executed by the workflow may differ from the code reviewed when the workflow was created. The risk arises from the third-party package supply chain, including compromise of the package publisher, a malicious package release, registry compromise, or unsafe registry configuration.
Attack Path
- An attacker compromises the relevant npm package, publisher account, release process, or configured package registry.
- The attacker publishes or serves a malicious version that satisfies the unpinned
npx audit-ciresolution. - A repository adopts and runs the documented CI workflow.
- During the security job,
npxresolves and downloads the mutable package version. - Package installation lifecycle code or the invoked executable runs with the CI runner's permissions.
- The malicious code accesses or alters runner-visible resources, subject to the workflow's token permissions and secret exposure controls.
Impact Assessment
Successful exploitation could provide arbitrary code execution within the CI runner's security context. Potentially exposed resources include checked-out source code, environment variables, generated build artifacts, package-registry credentials, and workflow tokens av ...[truncated 304 chars]
- Remediation
View remediation
Remediation Suggestions
-
Add
audit-cias a development dependency using an explicitly approved version and commit the generated lockfile. -
Install dependencies with
npm ciso CI uses the exact dependency graph recorded in the lockfile. -
Invoke the installed binary through a package script or an offline command, for example:
yaml - name: Install dependencies run: npm ci - name: Security Scan run: npm exec --offline audit-ci -- --high -
Review dependency updates through controlled pull requests and enable lockfile integrity verification.
-
Apply least-privilege workflow permissions and avoid exposing secrets to jobs that do not require them.
-
As defense in depth, pin third-party GitHub Actions to reviewed immutable commit SHAs rather than mutable version tags.
-
