Summary
All 16 GitHub Actions workflow files use actions pinned to mutable version tags (e.g. actions/checkout@v5, docker/build-push-action@v7) rather than immutable commit SHAs. A tag can be force-pushed by the action's maintainer or a compromised maintainer account, silently replacing the action with malicious code that runs with access to repository secrets.
Affected workflows and actions (representative sample)
Every workflow file in .github/workflows/ is affected. Key high-privilege actions:
| Action |
Current pin |
Risk |
actions/checkout@v5 |
mutable tag |
runs before any trust gates |
aws-actions/configure-aws-credentials@v6 |
mutable tag |
writes AWS credentials to env |
docker/build-push-action@v7 |
mutable tag |
builds and pushes production images |
snyk/actions/golang@0.4.0 |
mutable tag |
reads source code |
hashicorp/setup-terraform@v4 |
mutable tag |
runs terraform against cloud infra |
azure/login@v3 |
mutable tag |
writes Azure credentials to env |
google-github-actions/auth@v3 |
mutable tag |
writes GCP credentials to env |
github/codeql-action/upload-sarif@v4 |
mutable tag |
uploads security scan results |
Security-critical workflows that write secrets to the environment are highest priority: deploy-aws-lambda.yml, deploy-aws-fargate.yml, deploy-azure.yml, deploy-gcp.yml, ci.yml.
Remediation
Pin each action to its full 40-character commit SHA. Example for actions/checkout:
# Before
uses: actions/checkout@v5
# After
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v5.2.0
Tooling to automate this:
pinact (go install github.com/suzuki-shunsuke/pinact/cmd/pinact@latest) - updates all uses: lines in a directory
Dependabot with update-config for github-actions ecosystem automatically proposes SHA-pinned updates
Prioritize the four deploy workflows and ci.yml first as they run with production cloud credentials.
References
- SLSA Supply Chain Levels for Software Artifacts
- GitHub Security Hardening docs: "Using third-party actions"
- Affected files: all files under
.github/workflows/
Summary
All 16 GitHub Actions workflow files use actions pinned to mutable version tags (e.g.
actions/checkout@v5,docker/build-push-action@v7) rather than immutable commit SHAs. A tag can be force-pushed by the action's maintainer or a compromised maintainer account, silently replacing the action with malicious code that runs with access to repository secrets.Affected workflows and actions (representative sample)
Every workflow file in
.github/workflows/is affected. Key high-privilege actions:actions/checkout@v5aws-actions/configure-aws-credentials@v6docker/build-push-action@v7snyk/actions/golang@0.4.0hashicorp/setup-terraform@v4azure/login@v3google-github-actions/auth@v3github/codeql-action/upload-sarif@v4Security-critical workflows that write secrets to the environment are highest priority:
deploy-aws-lambda.yml,deploy-aws-fargate.yml,deploy-azure.yml,deploy-gcp.yml,ci.yml.Remediation
Pin each action to its full 40-character commit SHA. Example for
actions/checkout:Tooling to automate this:
pinact(go install github.com/suzuki-shunsuke/pinact/cmd/pinact@latest) - updates alluses:lines in a directoryDependabotwithupdate-configforgithub-actionsecosystem automatically proposes SHA-pinned updatesPrioritize the four deploy workflows and
ci.ymlfirst as they run with production cloud credentials.References
.github/workflows/