T08 · Insecure Dependencies
- Location
github-actions-generator.sh:18- Finding
Generated GitHub Actions Workflows Use Mutable Action References
- Content
View full analysis
Vulnerability Details
File Location:
github-actions-generator.sh, lines 18-19 and line 36
Vulnerability Type: Supply-chain risk caused by mutable GitHub Action references
Risk Level: MediumVulnerable Code
yaml # github-actions-generator.sh:18-19 - uses: actions/checkout@v4 - uses: actions/setup-node@v4yaml # github-actions-generator.sh:36 - uses: actions/checkout@v4Technical Analysis
The generator inserts GitHub Actions referenced through major-version tags such as
actions/checkout@v4andactions/setup-node@v4. A major-version tag is a mutable Git reference and can be moved to a different commit after the generated workflow has been reviewed.Consequently, the code executed by a workflow is not cryptographically bound to the revision originally inspected. If an upstream action repository, maintainer account, release process, or mutable tag is compromised, the generated workflow can execute modified third-party code without any corresponding change in the consuming repository.
This issue applies to both generated workflow types:
- The CI workflow uses mutable references for
actions/checkoutandactions/setup-node. - The deployment workflow uses a mutable reference for
actions/checkout.
Attack Path
- A user runs the generator and commits one of the generated workflow files.
- The workflow retains an action reference such as
actions/checkout@v4. - An attacker compromises the upstream action repository, a maintainer account, or another mechanism capable of changing the referenced tag.
- The mutable
v4tag is redirected to an attacker-controlled commit. - A push or pull-request event starts the generated workflow.
- GitHub Actions resolves the tag at runtime and executes the attacker-controlled action code.
- The malicious action attempts to access repository contents, build artifacts, the workflow token, environment da ...[truncated 981 chars]
- The CI workflow uses mutable references for
- Remediation
View remediation
Remediation Suggestions
Pin every third-party GitHub Action to a reviewed full commit SHA rather than a mutable branch, release, or major-version tag. Preserve the human-readable release version in a comment, for example:
yaml - uses: actions/checkout@FULL_40_CHARACTER_COMMIT_SHA # v4 - uses: actions/setup-node@FULL_40_CHARACTER_COMMIT_SHA # v4Apply the same remediation to the deployment workflow's
actions/checkoutreference.Additional hardening measures should include:
- Configure Dependabot or Renovate to propose controlled updates to pinned action SHAs.
- Review each proposed SHA update and verify that it belongs to the expected upstream release.
- Explicitly define minimal workflow
permissionsso a compromised action does not receive unnecessary repository write access. - Avoid exposing deployment credentials or other secrets to jobs that do not require them.
- Protect workflow-file changes through branch protection and mandatory code review.
- Consider organization-level policies that require actions to be pinned to immutable commit SHAs.
