Skip to content

sec: GitHub Actions not pinned to commit SHAs - supply-chain risk #415

Description

@cristim

Summary

All 16 GitHub Actions workflow files use actions pinned to mutable version tags (e.g. actions/checkout@v5, docker/build-push-action@v7) rather than immutable commit SHAs. A tag can be force-pushed by the action's maintainer or a compromised maintainer account, silently replacing the action with malicious code that runs with access to repository secrets.

Affected workflows and actions (representative sample)

Every workflow file in .github/workflows/ is affected. Key high-privilege actions:

Action Current pin Risk
actions/checkout@v5 mutable tag runs before any trust gates
aws-actions/configure-aws-credentials@v6 mutable tag writes AWS credentials to env
docker/build-push-action@v7 mutable tag builds and pushes production images
snyk/actions/golang@0.4.0 mutable tag reads source code
hashicorp/setup-terraform@v4 mutable tag runs terraform against cloud infra
azure/login@v3 mutable tag writes Azure credentials to env
google-github-actions/auth@v3 mutable tag writes GCP credentials to env
github/codeql-action/upload-sarif@v4 mutable tag uploads security scan results

Security-critical workflows that write secrets to the environment are highest priority: deploy-aws-lambda.yml, deploy-aws-fargate.yml, deploy-azure.yml, deploy-gcp.yml, ci.yml.

Remediation

Pin each action to its full 40-character commit SHA. Example for actions/checkout:

# Before
uses: actions/checkout@v5

# After
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683  # v5.2.0

Tooling to automate this:

  • pinact (go install github.com/suzuki-shunsuke/pinact/cmd/pinact@latest) - updates all uses: lines in a directory
  • Dependabot with update-config for github-actions ecosystem automatically proposes SHA-pinned updates

Prioritize the four deploy workflows and ci.yml first as they run with production cloud credentials.

References

  • SLSA Supply Chain Levels for Software Artifacts
  • GitHub Security Hardening docs: "Using third-party actions"
  • Affected files: all files under .github/workflows/

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions