You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
chore(ci): no workflow linter runs, so Actions expression injection is undetectable #1646
This is the systemic finding behind #1542, #1647 and #1649. Those three are instances; this is the reason all of them were invisible. Fixing them individually removes three bugs — adding a workflow linter prevents the entire class, including the next one nobody has found yet. Prioritise accordingly.
What
Nothing in this repo inspects .github/workflows/*.yml for GitHub Actions expression injection, or for any other workflow-level defect.
No actionlint and no zizmor in .github/workflows/ci.yml or in .pre-commit-config.yaml.
The Security Scanning job (ci.yml:282) runs govulncheck and gosec. Both are Go source scanners; neither opens a workflow file.
The trivy-config pre-commit hook targets Terraform / Dockerfile / Kubernetes misconfiguration, not Actions expression injection.
The check-yaml hook only proves the YAML parses.
That is why #1542 (critical, shell injection reaching production cloud credentials) and #1649 (critical, same shape via a release tag) both sat unflagged through every CI run on every push.
Evidence it would have been caught
actionlint with shellcheck on PATH, run against the pre-fix rollback.yml: exit 1. Against the fixed version (PR #1641): exit 0.
Current scope — 8 of 16 files fail today
Measured against origin/main @ 887d51fd6. A CI gate added without clearing these first would land red and get reverted, so the batch fix is part of this issue, not a follow-up:
The backlog is almost entirely shellcheck SC2086 (unquoted expansion, mostly >> $GITHUB_STEP_SUMMARY) and SC2129 (consecutive redirects), both info/style level — mechanical to clear.
Proposed
Clear the findings in the 8 files above in one batch commit. Do not gate-suppress them (only-new-issues, blanket disables) — that is the masking-CI-debt anti-pattern.
What
Nothing in this repo inspects
.github/workflows/*.ymlfor GitHub Actions expression injection, or for any other workflow-level defect.actionlintand nozizmorin.github/workflows/ci.ymlor in.pre-commit-config.yaml.Security Scanningjob (ci.yml:282) runsgovulncheckandgosec. Both are Go source scanners; neither opens a workflow file.trivy-configpre-commit hook targets Terraform / Dockerfile / Kubernetes misconfiguration, not Actions expression injection.check-yamlhook only proves the YAML parses.That is why #1542 (critical, shell injection reaching production cloud credentials) and #1649 (critical, same shape via a release tag) both sat unflagged through every CI run on every push.
Evidence it would have been caught
actionlintwithshellcheckon PATH, run against the pre-fixrollback.yml: exit 1. Against the fixed version (PR #1641): exit 0.Current scope — 8 of 16 files fail today
Measured against
origin/main@887d51fd6. A CI gate added without clearing these first would land red and get reverted, so the batch fix is part of this issue, not a follow-up:ci.ymldatabase-migration.ymldeploy-all.ymldeploy-aws-fargate.ymldeploy-aws-lambda.ymldeploy-azure.ymldeploy-gcp.ymlrollback.ymlaws_sanity.yml,azure_sanity.yml,cleanup-staging.yml,destroy-fargate-dev.yml,frontend-build.yml,frontend-build-sentinel.yml,frontend-e2e.yml,pre-commit.ymlReproduce (note: capture
rc=$?on its own statement — a$(basename …)in the same line overwrites$?and reports every file as passing):The backlog is almost entirely
shellcheckSC2086 (unquoted expansion, mostly>> $GITHUB_STEP_SUMMARY) and SC2129 (consecutive redirects), both info/style level — mechanical to clear.Proposed
only-new-issues, blanket disables) — that is the masking-CI-debt anti-pattern.actionlintto.pre-commit-config.yamlvia the upstreamrhysd/actionlinthook, pinned to an explicit version per the repo's no-@latestconvention.shellcheckmust be available or actionlint silently skips shell linting — which would have missed sec(ci): rollback.yml interpolates the free-text reason input into run blocks in a job holding id-token write #1542.zizmor. This is the one that actually closes the detection gap:actionlintonly catches this class indirectly, via shellcheck on the expanded script.zizmorhas a dedicatedtemplate-injectionrule that names the defect, plusdangerous-triggersandexcessive-permissions— the latter two would also have flagged the workflow-levelid-token: writein sec(ci): deploy-aws-lambda.yml interpolates a release tag name into a run block in an ungated job holding id-token write #1649 and sec(ci): database-migration.yml interpolates inputs into run blocks behind a post-interpolation guard #1647.Instances of the class found so far: #1542 (fixed, PR #1641), #1649 (fixed, PR #1657), #1647 (open). Related: #1591, LeanerCloud/cloud-commitments-platform#139.