Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/release-on-merge.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ jobs:
- uses: pnpm/action-setup@v5
with:
version: 7.6.0
- uses: actions/setup-node@v6
- uses: actions/setup-node@v7

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Semgrep identified an issue in your code:

The actions/setup-node@v7 reference uses a mutable tag instead of a pinned commit SHA, allowing the action owner to silently update what code runs in your workflow.

More details about this

The actions/setup-node@v7 step uses a mutable version tag (v7) instead of a pinned commit SHA. Since v7 is a floating tag, the action owner can silently update what code runs under this tag without your knowledge.

Attack scenario: An attacker who compromises the actions/setup-node repository could push a malicious update to the v7 tag. The next time this workflow runs, your job would execute the compromised version of setup-node, potentially allowing the attacker to:

  1. Inject malicious code into your build environment
  2. Exfiltrate your GITHUB_TOKEN (which has permissions to push to your repository)
  3. Modify your source code or build artifacts before they're deployed

This mirrors real-world supply-chain attacks like the trivy-action and kics-github-action compromises, where attackers gained access through mutable action references and used it to push malicious code to users' repositories.

To resolve this comment:

✨ Commit fix suggestion
  1. Replace the mutable action reference actions/setup-node@v7 with a full 40-character commit SHA for the exact v7 release you intend to trust, for example uses: actions/setup-node@<full-40-char-sha>.

  2. Keep the existing with block unchanged so only the action reference changes.

  3. Get the SHA from the actions/setup-node release or tag you want to use, then pin that exact commit in the workflow file. Pinning to a commit prevents the action owner from moving v7 to different code later.

💬 Ignore this finding

Reply with Semgrep commands to ignore this finding.

  • /fp <comment> for false positive
  • /ar <comment> for acceptable risk
  • /other <comment> for all other reasons

Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by github-actions-mutable-action-tag.

Need help? Review go/semgrep-playbook or Reach out in #security-vulnerabilities on Slack.

You can view more details about this finding in the Semgrep AppSec Platform.

with:
node-version: '16'
cache: 'pnpm'
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/test-on-pull-request.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ jobs:
- uses: pnpm/action-setup@v5
with:
version: 7.6.0
- uses: actions/setup-node@v6
- uses: actions/setup-node@v7

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Semgrep identified an issue in your code:

GitHub Actions step uses mutable version tag v7 instead of a pinned commit SHA, allowing the action owner to silently update the tag to malicious code and compromise your CI/CD pipeline.

More details about this

The GitHub Actions step references actions/setup-node using the mutable version tag v7, which can be silently repointed to a different commit by the action owner without your knowledge or approval.

Exploit scenario:

  1. An attacker gains control of the actions/setup-node repository or the GitHub account that maintains it
  2. They update the v7 tag to point to a malicious commit containing backdoored code that steals secrets or injects code into your build
  3. Your workflow runs and uses the compromised v7 tag—since tags can be moved, you automatically run the attacker's malicious version
  4. The backdoored Node.js setup step now has access to GITHUB_TOKEN and repository secrets, allowing the attacker to exfiltrate them or modify your code

This mirrors real attacks like the trivy-action and kics-github-action compromises, where attackers exploited mutable tag references to inject malicious code into CI/CD pipelines.

To resolve this comment:

✨ Commit fix suggestion
  1. Replace the mutable action reference actions/setup-node@v7 with a full 40-character commit SHA for the exact action version you want to keep using.
  2. Resolve the SHA from the v7 release in the actions/setup-node repository, then update the step to use uses: actions/setup-node@<full-40-char-sha>.
  3. Keep the existing with: settings unchanged, for example node-version: '16' and cache: 'pnpm', and only change the uses: value. Pinning to a commit SHA prevents the action owner from silently moving the tag to different code later.
💬 Ignore this finding

Reply with Semgrep commands to ignore this finding.

  • /fp <comment> for false positive
  • /ar <comment> for acceptable risk
  • /other <comment> for all other reasons

Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by github-actions-mutable-action-tag.

Need help? Review go/semgrep-playbook or Reach out in #security-vulnerabilities on Slack.

You can view more details about this finding in the Semgrep AppSec Platform.

with:
node-version: '16'
cache: 'pnpm'
Expand Down
Loading