feat(enrichment): detect GitHub Actions workflow-injection and pwn-request risk#3398
Closed
joaovictor91123 wants to merge 1 commit into
Closed
feat(enrichment): detect GitHub Actions workflow-injection and pwn-request risk#3398joaovictor91123 wants to merge 1 commit into
joaovictor91123 wants to merge 1 commit into
Conversation
…quest risk Adds a REES analyzer that flags the pull_request_target/workflow_run "pwn request" pattern: checkout of an untrusted PR head, unsafe shell interpolation of untrusted event fields, and a missing permissions narrowing block on an elevated-trust trigger.
Contributor
|
Superagent didn't find any vulnerabilities or security issues in this PR. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds
review-enrichment/src/analyzers/workflow-injection.ts, a new REES analyzer that flags the GitHub Actions "pwn request" trust-boundary pattern: apull_request_target/workflow_runworkflow (which runs with the base repo's secrets and token even for a fork PR) that checks out the untrusted PR head, interpolates untrusted event fields (PR title/body/head ref, issue/comment body) directly into arun:shell step instead of viaenv:, or carries no narrowedpermissions:block. Registered inregistry.ts/analyzer-metadata.jsonalongside the existingactionPin/iacMisconfiganalyzers, whose shape it follows.No issue is linked: this repo's
linkedIssuePolicyispreferred, not required, and the proposal, rationale, and full test plan are self-contained in this PR. I checked for duplicates first: PR #2668 (workflowPermissions) proposed a related but narrower analyzer (permission-escalation flags and bare trigger-declaration detection) and was closed for a specific correctness bug in its trigger tracking; it never merged, so nothing in main covers this today. This PR does not overlap it — it targets the untrusted-checkout and shell-injection vectors #2668 didn't attempt — and its own trigger detection reads both added and unchanged context lines in a hunk (not just added lines gated behind seeingon:in the same hunk), which avoids the specific defect that got #2668 closed.Scope
type(scope): short summaryConventional Commit format, for examplefix(api): restore profile access checks.CONTRIBUTING.mdand does not reintroduce GitHub Pages, VitePress,site/, orCNAME.Validation
git diff --checknpm run actionlintnpm run typechecknpm run test:coveragelocally;codecov/patchrequires ≥99% coverage of the lines AND branches you changed (aim for 100% on your diff so CI variance does not fail near the threshold). Global coverage is a non-blocking trend with a loose 90% backstop, not the gate.npm run test:workersnpm run build:mcpnpm run test:mcp-packnpm run ui:openapi:checknpm run ui:lintnpm run ui:typechecknpm run ui:buildnpm audit --audit-level=moderateIf any required check was skipped, explain why:
npm run test:mcp-packcrashes on my local Windows dev machine with a pre-existing, unrelatedERR_INVALID_ARG_TYPEinscripts/check-mcp-package.mjsthat I confirmed reproduces identically on a clean, unmodifiedmaincheckout — it is a local Node/Windows environment issue, not something this PR introduces. Likewisenpm run ui:lintand part ofnpm run test:coverageshow failures on this machine (CRLF-vs-LF noise across the wholeapps/gittensory-uitree fromcore.autocrlf, and ~30 shell/script-based test files that needbash/sentry-cli/dockertooling this Windows box doesn't have); I verified every one of these also fails identically on a cleanmaincheckout, so I'm listing them as run rather than skipped, with this caveat. The new analyzer's own test suite (review-enrichment/test/workflow-injection.test.ts, run vianpm run rees:test) passes in full (10/10), and the fullreview-enrichmentsuite is green apart from those same 2 pre-existingsentry-upload.test.tsfailures.Safety
UI Evidencesection below with JPG/JPEG or PNG screenshots arranged as organized, captioned, clickable thumbnails. SVG screenshots are not used as review evidence. Review-only screenshots or recordings are not committed to the repository.UI Evidence
Not applicable — this PR adds a new REES analyzer (backend/enrichment logic) with an accompanying
apps/gittensory-ui/src/lib/rees-analyzers.tsmetadata entry, but no new visible UI surface.Notes