Skip to content

Fix possible this workflow uses secrets: inherit to pass all of the calling workflow's s… in build-docker.ym - #1438

Open
begininvoke wants to merge 1 commit into
zedeus:masterfrom
begininvoke:redgem/security-fix-fc09bab2
Open

Fix possible this workflow uses secrets: inherit to pass all of the calling workflow's s… in build-docker.ym#1438
begininvoke wants to merge 1 commit into
zedeus:masterfrom
begininvoke:redgem/security-fix-fc09bab2

Conversation

@begininvoke

Copy link
Copy Markdown

Small change to .github/workflows/build-docker.yml — a scan flagged the code below and it looked genuine. It is around line 20.

The workflow forwards all repository secrets to a reusable workflow using secrets: inherit. This grants the called workflow unnecessary privileged access; if the reusable workflow is compromised or originates from an untrusted source, an attacker could exfiltrate any secret (CWE‑250). Because secrets often include deployment tokens, API keys, and credentials, the impact can be full repository compromise. The risk is classified as high due to the broad exposure and difficulty in revoking after leakage.

Removed secrets: inherit to enforce least privilege; the tests workflow will receive no secrets unless explicitly added.

For reference: rule yaml.github-actions.security.secrets-inherit.secrets-inherit, CWE-250 (Execution with Unnecessary Privileges). Rated high.

I do not know the codebase, so please check the change fits how the rest of it works. Happy to adjust it or close this if the reasoning is off.


Found with automated scanning (RedGem) and reviewed before opening. If it is not useful, closing it is completely fine.

…he calling workflow's secrets to a reusable workflo
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant