T08 · Insecure Dependencies
- Location
SKILL.md:128- Finding
Mutable GitHub Actions References Create a CI Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 128-129
Vulnerability Type: T08: Insecure Dependencies
Risk Level: MediumComplete Code Snippet:
yaml - uses: actions/checkout@v4 - uses: foundry-rs/foundry-toolchain@v1Technical Analysis
The proposed GitHub Actions workflow references third-party actions through mutable version tags instead of immutable full commit SHA values. A tag may resolve to code that differs from the version originally reviewed. Following the documented workflow therefore causes CI to retrieve and execute external components whose effective implementations can change after this Skill has been audited.
This is particularly significant because GitHub Actions execute within the CI job context and may have access to the checked-out repository, workflow artifacts, the
GITHUB_TOKEN, and any secrets intentionally exposed to the job. The risk depends on the repository's workflow permissions, event triggers, secret configuration, and upstream action security.Attack Path
- A user adopts the workflow documented in
SKILL.md. - An attacker compromises an upstream action repository, release process, maintainer account, or mutable version reference.
- The referenced
@v4or@v1tag begins resolving to modified action code. - A push or pull request triggers the audit workflow.
- GitHub retrieves and executes the modified action in the CI runner.
- The malicious action accesses resources available to the job, potentially reads repository content or exposed credentials, modifies artifacts, or falsifies build and test results.
Impact Assessment
Successful exploitation can execute attacker-controlled code with the permissions of the affected CI job. The potential scope includes repository source code, generated artifacts, writable repository operations allowed by
GITHUB_TOKEN, and workflow secrets made available in that execution context. It may also c ...[truncated 374 chars]- A user adopts the workflow documented in
- Remediation
View remediation
Remediation Suggestions
- Pin every GitHub Action to a reviewed full commit SHA rather than a mutable tag:
yaml - uses: actions/checkout@<reviewed-full-commit-sha> - uses: foundry-rs/foundry-toolchain@<reviewed-full-commit-sha> - Add comments beside each SHA recording the corresponding release version for maintainability.
- Use dependency-update automation to submit reviewed pull requests when newer action revisions become available.
- Declare least-privilege workflow permissions explicitly, using
permissions: contents: readunless additional access is demonstrably required. - Do not expose privileged secrets to workflows triggered by untrusted pull requests.
- Review the source and provenance of action updates before changing pinned revisions.
- Apply branch protection and require human review for workflow-file modifications.
- Pin every GitHub Action to a reviewed full commit SHA rather than a mutable tag:
