T08 · Insecure Dependencies
- Location
SKILL.md:64- Finding
Unpinned Third-Party Dependencies Allow Supply-Chain Code Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 64-75, 126, 136-139, 150-152, 160, and 188-190
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumThe deployment guidance recommends GitHub Actions referenced by mutable major-version tags and npm packages installed or executed without exact versions or integrity controls.
Vulnerable Code
yaml - name: Checkout uses: actions/checkout@v4 - name: Setup Pages uses: actions/configure-pages@v4 - name: Upload artifact uses: actions/upload-pages-artifact@v3 with: path: 'website' - name: Deploy to GitHub Pages uses: actions/deploy-pages@v4bash npm install -g html-minifier clean-css-cli uglify-js html-minifier --collapse-whitespace website/index.html -o website/index.html cleancss -o website/style.css website/style.css uglifyjs website/script.js -o website/script.jsyaml - name: Cache dependencies uses: actions/cache@v3 with: path: ~/.npm key: ${{ runner.os }}-npm-${{ hashFiles('**/package-lock.json') }}yaml - name: Deploy Preview uses: rossjrw/pr-preview-action@v1 with: source-dir: websitebash npx squoosh-cli website/images/*.jpg --webp autoyaml - name: Run Lighthouse uses: treosh/lighthouse-ci-action@v9 with: urls: https://yourdomain.comTechnical Analysis
GitHub Action references such as
@v4,@v3,@v1, and@v9are mutable tags rather than immutable commit identifiers. If an upstream repository or publisher account is compromised, an attacker may move or replace a referenced tag so that future workflow runs execute different code from the code originally reviewed.The command
npm install -g html-minifier clean-css-cli uglify-jsresolves package versions from the npm registry at execution time. It does not use exact versions, a committed lockfile, or integrity verification. ...[truncated 2331 chars]- Remediation
View remediation
Remediation Suggestions
-
Pin every GitHub Action to a reviewed full commit SHA instead of a mutable version tag. Retain the release version in a comment for maintainability, for example:
yaml uses: actions/checkout@REVIEWED_FULL_COMMIT_SHA # v4.x.x -
Apply SHA pinning to both GitHub-maintained and third-party actions, especially:
actions/checkoutactions/configure-pagesactions/upload-pages-artifactactions/deploy-pagesactions/cacherossjrw/pr-preview-actiontreosh/lighthouse-ci-action
-
Review third-party action source code and repository ownership before adoption. Prefer first-party actions where equivalent functionality exists.
-
Add required npm tools as exact-version development dependencies rather than installing them globally:
bash npm install --save-dev --save-exact html-minifier clean-css-cli uglify-js -
Commit the generated
package-lock.jsonand install dependencies in CI using:bash npm ci -
Replace ad hoc
npx squoosh-cliexecution with a reviewed, exact-version dependency invoked from the locked project installation. Verify the package name, publisher, source repository, and expected integrity before use. -
Use dependency update automation that proposes reviewed SHA and version changes rather than silently tracking mutable upstream tags.
-
Preserve least privilege by granting
pages: writeandid-token: writeonly to the deployment job and environment that require them. Configure protected GitHub environments and deployment approvals where appropriate.
-
