Skip to content

fix: extract 10 unsafe expression(s) to env vars#49808

Closed
dagecko wants to merge 1 commit intospring-projects:mainfrom
dagecko:runner-guard/fix-ci-security
Closed

fix: extract 10 unsafe expression(s) to env vars#49808
dagecko wants to merge 1 commit intospring-projects:mainfrom
dagecko:runner-guard/fix-ci-security

Conversation

@dagecko
Copy link

@dagecko dagecko commented Mar 26, 2026

Security: Harden GitHub Actions workflows

Hey, we found some CI/CD security issues in this repo's workflows using Runner Guard, our open-source CI/CD security scanner at Vigilant. These are the same vulnerability classes being actively exploited right now in the tj-actions, Trivy, LiteLLM supply chain attack chain. We scanned the top 50K repos on GitHub and over 20,000 have this same problem. We're trying to get fixes out to as many maintainers as possible before more repos get hit.

This PR fixes what we could automatically, and flags anything else that needs a manual look. There's a real person behind this PR, we're actively checking back on comments so if you have any questions just drop them here and we'll respond.

Fixes applied (in this PR)

Rule Severity File Description
RGS-002 high .github/workflows/build-and-deploy-snapshot.yml Extracted 1 unsafe expression(s) to env vars
RGS-002 high .github/workflows/distribute.yml Extracted 4 unsafe expression(s) to env vars
RGS-002 high .github/workflows/release-milestone.yml Extracted 1 unsafe expression(s) to env vars
RGS-002 high .github/workflows/release.yml Extracted 1 unsafe expression(s) to env vars
RGS-002 high .github/workflows/trigger-docs-build.yml Extracted 3 unsafe expression(s) to env vars

Advisory: additional findings (manual review recommended)

| Rule | Severity | File | Description |
| RGS-012 | high | .github/workflows/distribute.yml | Secret Exfiltration via Outbound HTTP Request |
| RGS-012 | high | .github/workflows/distribute.yml | Secret Exfiltration via Outbound HTTP Request |

Why this matters

GitHub Actions workflows that use untrusted input in run: blocks, expose
secrets inline, or use unpinned third-party actions are vulnerable to
code injection, credential theft, and supply chain attacks. These are the same
vulnerability classes exploited in the tj-actions/changed-files incident
and subsequent supply chain attacks, which compromised CI secrets across
thousands of repositories.

How to verify

Review the diff — each change is mechanical and preserves workflow behavior:

  • Expression extraction (RGS-002/008/014): Moves ${{ }} expressions from
    run: blocks into env: mappings, preventing shell injection

Run brew install Vigilant-LLC/tap/runner-guard && runner-guard scan . or install from the
repo to verify.


Found by Runner Guard | Built by Vigilant Cyber Security | Learn more

If this PR is not welcome, just close it -- we won't send another.

Automated security fixes applied by Runner Guard (https://github.com/Vigilant-LLC/runner-guard).

Changes:
 .github/workflows/build-and-deploy-snapshot.yml |  3 ++-
 .github/workflows/distribute.yml                | 11 +++++++++--
 .github/workflows/release-milestone.yml         |  3 ++-
 .github/workflows/release.yml                   |  3 ++-
 .github/workflows/trigger-docs-build.yml        |  5 ++++-
 5 files changed, 19 insertions(+), 6 deletions(-)
@spring-projects-issues spring-projects-issues added the status: waiting-for-triage An issue we've not yet triaged label Mar 26, 2026
@dagecko dagecko closed this by deleting the head repository Mar 26, 2026
@philwebb philwebb added status: invalid An issue that we don't feel is valid and removed status: waiting-for-triage An issue we've not yet triaged labels Mar 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

status: invalid An issue that we don't feel is valid

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants