chore(deps): bump the github-actions group with 38 updates - #907
dependabot[bot] wants to merge 1 commit into
Conversation
Updates the requirements on [actions/checkout](https://github.com/actions/checkout), [dtolnay/rust-toolchain](https://github.com/dtolnay/rust-toolchain), [actions/upload-artifact](https://github.com/actions/upload-artifact), [actions/setup-java](https://github.com/actions/setup-java), [gradle/actions/setup-gradle](https://github.com/gradle/actions), [actions/download-artifact](https://github.com/actions/download-artifact), [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action), [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action), [docker/login-action](https://github.com/docker/login-action), [docker/metadata-action](https://github.com/docker/metadata-action), [docker/build-push-action](https://github.com/docker/build-push-action), [actions/setup-node](https://github.com/actions/setup-node), [pnpm/action-setup](https://github.com/pnpm/action-setup), [peter-evans/create-pull-request](https://github.com/peter-evans/create-pull-request), [dallay/common-actions/.github/workflows/cleanup-cache.yml](https://github.com/dallay/common-actions), [github/codeql-action](https://github.com/github/codeql-action), [dallay/common-actions/.github/workflows/dependabot-auto-merge.yml](https://github.com/dallay/common-actions), [actions/dependency-review-action](https://github.com/actions/dependency-review-action), [actions/upload-pages-artifact](https://github.com/actions/upload-pages-artifact), [actions/deploy-pages](https://github.com/actions/deploy-pages), [github/codeql-action/upload-sarif](https://github.com/github/codeql-action), [actions/github-script](https://github.com/actions/github-script), [dallay/common-actions/.github/workflows/greetings.yml](https://github.com/dallay/common-actions), [actions/create-github-app-token](https://github.com/actions/create-github-app-token), [actions/cache](https://github.com/actions/cache), [lycheeverse/lychee-action](https://github.com/lycheeverse/lychee-action), [actions/cache/save](https://github.com/actions/cache), [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action), [google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml](https://github.com/google/osv-scanner-action), [dallay/common-actions/.github/workflows/pr-size-labeler.yml](https://github.com/dallay/common-actions), [codecov/codecov-action](https://github.com/codecov/codecov-action), [googleapis/release-please-action](https://github.com/googleapis/release-please-action), [taiki-e/install-action](https://github.com/taiki-e/install-action), [gradle/actions/dependency-submission](https://github.com/gradle/actions), [dallay/common-actions/.github/workflows/semantic-pull-request.yml](https://github.com/dallay/common-actions), [SonarSource/sonarqube-scan-action](https://github.com/sonarsource/sonarqube-scan-action), [SonarSource/sonarqube-quality-gate-action](https://github.com/sonarsource/sonarqube-quality-gate-action) and [dallay/common-actions/.github/workflows/stale.yml](https://github.com/dallay/common-actions) to permit the latest version. Updates `actions/checkout` from 6.0.2 to 7.0.1 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@de0fac2...3d3c42e) Updates `dtolnay/rust-toolchain` to d1031067263f94b142dd6c0ce24c5eb9d02d52a0 - [Release notes](https://github.com/dtolnay/rust-toolchain/releases) - [Commits](https://github.com/dtolnay/rust-toolchain/commits/d1031067263f94b142dd6c0ce24c5eb9d02d52a0) Updates `actions/upload-artifact` from 4.6.2 to 7.0.1 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@ea165f8...043fb46) Updates `actions/setup-java` from 5.2.0 to 6.0.1 - [Release notes](https://github.com/actions/setup-java/releases) - [Commits](actions/setup-java@be666c2...de7274f) Updates `gradle/actions/setup-gradle` from 5.0.2 to 6.3.0 - [Release notes](https://github.com/gradle/actions/releases) - [Commits](gradle/actions@0723195...9c97196) Updates `actions/download-artifact` from 7.0.0 to 8.0.1 - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](actions/download-artifact@37930b1...3e5f45b) Updates `docker/setup-qemu-action` from 3.7.0 to 4.3.0 - [Release notes](https://github.com/docker/setup-qemu-action/releases) - [Commits](docker/setup-qemu-action@c7c5346...1f40c72) Updates `docker/setup-buildx-action` from 3.12.0 to 4.3.0 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](docker/setup-buildx-action@8d2750c...37fe631) Updates `docker/login-action` from 3.7.0 to 4.6.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@c94ce9f...dbcb813) Updates `docker/metadata-action` from 5.10.0 to 6.2.0 - [Release notes](https://github.com/docker/metadata-action/releases) - [Commits](docker/metadata-action@c299e40...dc80280) Updates `docker/build-push-action` from 6.19.2 to 7.3.0 - [Release notes](https://github.com/docker/build-push-action/releases) - [Commits](docker/build-push-action@10e90e3...53b7df9) Updates `actions/setup-node` from 6.3.0 to 7.0.0 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@53b8394...8207627) Updates `pnpm/action-setup` from 4.2.0 to 6.1.0 - [Release notes](https://github.com/pnpm/action-setup/releases) - [Commits](pnpm/action-setup@41ff726...ea17c68) Updates `peter-evans/create-pull-request` from 8.0.0 to 8.1.1 - [Release notes](https://github.com/peter-evans/create-pull-request/releases) - [Commits](peter-evans/create-pull-request@98357b1...5f6978f) Updates `dallay/common-actions/.github/workflows/cleanup-cache.yml` from 2.0.0 to 2.2.4 - [Release notes](https://github.com/dallay/common-actions/releases) - [Commits](dallay/common-actions@6ecd716...6906025) Updates `github/codeql-action` from 3 to 4 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@v3...v4) Updates `dallay/common-actions/.github/workflows/dependabot-auto-merge.yml` from 2.0.0 to 2.2.4 - [Release notes](https://github.com/dallay/common-actions/releases) - [Commits](dallay/common-actions@v2.0.0...v2.2.4) Updates `actions/dependency-review-action` from 4.8.3 to 5.0.0 - [Release notes](https://github.com/actions/dependency-review-action/releases) - [Commits](actions/dependency-review-action@05fe457...a1d282b) Updates `actions/upload-pages-artifact` from 4.0.0 to 5.0.0 - [Release notes](https://github.com/actions/upload-pages-artifact/releases) - [Commits](actions/upload-pages-artifact@7b1f4a7...fc324d3) Updates `actions/deploy-pages` from 4.0.5 to 5.0.1 - [Release notes](https://github.com/actions/deploy-pages/releases) - [Commits](actions/deploy-pages@d6db901...368f825) Updates `github/codeql-action/upload-sarif` from 4.31.10 to 4.38.0 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@cdefb33...b96794f) Updates `actions/github-script` from 8.0.0 to 9.0.0 - [Release notes](https://github.com/actions/github-script/releases) - [Commits](actions/github-script@ed59741...3a2844b) Updates `dallay/common-actions/.github/workflows/greetings.yml` from 2.0.0 to 2.2.4 - [Release notes](https://github.com/dallay/common-actions/releases) - [Commits](dallay/common-actions@6ecd716...6906025) Updates `actions/create-github-app-token` from 2.2.1 to 3.2.0 - [Release notes](https://github.com/actions/create-github-app-token/releases) - [Changelog](https://github.com/actions/create-github-app-token/blob/main/CHANGELOG.md) - [Commits](actions/create-github-app-token@v2.2.1...bcd2ba4) Updates `actions/cache` from 4.2.1 to 6.1.0 - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@0c907a7...55cc834) Updates `lycheeverse/lychee-action` from 2.8.0 to 2.9.0 - [Release notes](https://github.com/lycheeverse/lychee-action/releases) - [Commits](lycheeverse/lychee-action@8646ba3...e747777) Updates `actions/cache/save` from 4.2.1 to 6.1.0 - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@0c907a7...55cc834) Updates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from eb5b619bb565d10623076caba5263750fde3c790 to 8e5cf47b818121e8b405931c82126c2630b0b20d - [Release notes](https://github.com/google/osv-scanner-action/releases) - [Commits](google/osv-scanner-action@eb5b619...8e5cf47) Updates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml` from eb5b619bb565d10623076caba5263750fde3c790 to 8e5cf47b818121e8b405931c82126c2630b0b20d - [Release notes](https://github.com/google/osv-scanner-action/releases) - [Commits](google/osv-scanner-action@eb5b619...8e5cf47) Updates `dallay/common-actions/.github/workflows/pr-size-labeler.yml` from 2.0.0 to 2.2.4 - [Release notes](https://github.com/dallay/common-actions/releases) - [Commits](dallay/common-actions@6ecd716...6906025) Updates `codecov/codecov-action` from 5.5.3 to 7.0.0 - [Release notes](https://github.com/codecov/codecov-action/releases) - [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md) - [Commits](codecov/codecov-action@1af5884...fb8b358) Updates `googleapis/release-please-action` from 4.4.0 to 5.0.0 - [Release notes](https://github.com/googleapis/release-please-action/releases) - [Changelog](https://github.com/googleapis/release-please-action/blob/main/CHANGELOG.md) - [Commits](googleapis/release-please-action@16a9c90...45996ed) Updates `taiki-e/install-action` from 2.68.14 to 2.87.9 - [Release notes](https://github.com/taiki-e/install-action/releases) - [Commits](taiki-e/install-action@v2.68.14...v2.87.9) Updates `gradle/actions/dependency-submission` from 5.0.2 to 6.3.0 - [Release notes](https://github.com/gradle/actions/releases) - [Commits](gradle/actions@0723195...9c97196) Updates `dallay/common-actions/.github/workflows/semantic-pull-request.yml` from 2.0.0 to 2.2.4 - [Release notes](https://github.com/dallay/common-actions/releases) - [Commits](dallay/common-actions@v2.0.0...v2.2.4) Updates `SonarSource/sonarqube-scan-action` from 6.0.0 to 8.2.1 - [Release notes](https://github.com/sonarsource/sonarqube-scan-action/releases) - [Commits](SonarSource/sonarqube-scan-action@fd88b7d...2291811) Updates `SonarSource/sonarqube-quality-gate-action` from 1.1.0 to 1.2.1 - [Release notes](https://github.com/sonarsource/sonarqube-quality-gate-action/releases) - [Commits](SonarSource/sonarqube-quality-gate-action@d304d05...7a5fffe) Updates `dallay/common-actions/.github/workflows/stale.yml` from 2.0.0 to 2.2.4 - [Release notes](https://github.com/dallay/common-actions/releases) - [Commits](dallay/common-actions@6ecd716...6906025) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: dtolnay/rust-toolchain dependency-version: d1031067263f94b142dd6c0ce24c5eb9d02d52a0 dependency-type: direct:production dependency-group: github-actions - dependency-name: actions/upload-artifact dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/setup-java dependency-version: 6.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: gradle/actions/setup-gradle dependency-version: 6.3.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/download-artifact dependency-version: 8.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: docker/setup-qemu-action dependency-version: 4.3.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: docker/setup-buildx-action dependency-version: 4.3.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: docker/login-action dependency-version: 4.6.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: docker/metadata-action dependency-version: 6.2.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: docker/build-push-action dependency-version: 7.3.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/setup-node dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: pnpm/action-setup dependency-version: 6.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: peter-evans/create-pull-request dependency-version: 8.1.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: dallay/common-actions/.github/workflows/cleanup-cache.yml dependency-version: 2.2.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: github/codeql-action dependency-version: '4' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: dallay/common-actions/.github/workflows/dependabot-auto-merge.yml dependency-version: 2.2.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/dependency-review-action dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/upload-pages-artifact dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/deploy-pages dependency-version: 5.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.38.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/github-script dependency-version: 9.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: dallay/common-actions/.github/workflows/greetings.yml dependency-version: 2.2.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/create-github-app-token dependency-version: 3.2.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/cache dependency-version: 6.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: lycheeverse/lychee-action dependency-version: 2.9.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/cache/save dependency-version: 6.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml dependency-version: 8e5cf47b818121e8b405931c82126c2630b0b20d dependency-type: direct:production dependency-group: github-actions - dependency-name: google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml dependency-version: 8e5cf47b818121e8b405931c82126c2630b0b20d dependency-type: direct:production dependency-group: github-actions - dependency-name: dallay/common-actions/.github/workflows/pr-size-labeler.yml dependency-version: 2.2.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: codecov/codecov-action dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: googleapis/release-please-action dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: taiki-e/install-action dependency-version: 2.87.9 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: gradle/actions/dependency-submission dependency-version: 6.3.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: dallay/common-actions/.github/workflows/semantic-pull-request.yml dependency-version: 2.2.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: SonarSource/sonarqube-scan-action dependency-version: 8.2.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: SonarSource/sonarqube-quality-gate-action dependency-version: 1.2.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: dallay/common-actions/.github/workflows/stale.yml dependency-version: 2.2.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
|
It seems you edited the limitation files. These files aren't open for contributions. If you think they should be, feel free to reply here. |
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Thank you for contributing to this project with this PR, welcome to the community and the amazing world of open source! |
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
| - name: 🔍 Run CodeQL Analysis | ||
| if: matrix.language != 'java-kotlin' | ||
| uses: github/codeql-action/analyze@v3 | ||
| uses: github/codeql-action/analyze@v4 |
There was a problem hiding this comment.
Semgrep identified a blocking 🔴 issue in your code:
GitHub Actions step uses mutable tag @v4 instead of a pinned commit SHA, allowing the action owner to silently redirect to malicious code and compromise your CI/CD pipeline.
More details about this
The GitHub Actions workflow is using uses: github/codeql-action/analyze@v4, which pins to a mutable tag (v4) rather than a specific commit SHA. This means the action owner can silently redirect what code runs in your workflow without your knowledge.
Here's how an attacker could exploit this:
-
Compromise the codeql-action repository: An attacker gains write access to the GitHub repository hosting
github/codeql-action(or tricks GitHub into transferring ownership). -
Repoint the
v4tag: The attacker updates thev4tag to point to a malicious commit they've created that includes backdoored code (e.g., code that exfiltrates secrets from the GitHub Actions environment). -
Your workflow silently runs the backdoor: The next time your workflow runs, GitHub Actions resolves
@v4to the attacker's malicious commit. Youranalyzestep now runs arbitrary code with access tosecretsand repository data. -
Extract sensitive data: The malicious
github/codeql-action/analyzecould steal environment variables containing API keys, access tokens, or commit credentials that were set up for your repository.
This has happened in the real world—the trivy-action and kics-github-action projects both experienced compromises where tags were repointed to inject malicious code into CI/CD pipelines.
To resolve this comment:
✨ Commit fix suggestion
- Replace the mutable reference
github/codeql-action/analyze@v4with a full 40-character commit SHA for thev4release, for examplegithub/codeql-action/analyze@<full-40-character-sha>. - Update both
uses: github/codeql-action/analyze@v4entries in this workflow so they point to the same pinned commit SHA. - Get the correct SHA from the
github/codeql-actionrepository’sv4release or tags page, and use the exact commit value instead of the tag name. This prevents the action from changing silently if the tag is moved. - Keep the action name and step conditions the same; only change the part after
@, for exampleuses: github/codeql-action/analyze@8ade135a41bc03ea155e62e844d188df1ea18608.
💬 Ignore this finding
Reply with Semgrep commands to ignore this finding.
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by github-actions-mutable-action-tag.
You can view more details about this finding in the Semgrep AppSec Platform.
| if: > | ||
| steps.gradle_build_java_kotlin.outcome == 'success' | ||
| uses: github/codeql-action/analyze@v3 | ||
| uses: github/codeql-action/analyze@v4 |
There was a problem hiding this comment.
Semgrep identified a blocking 🔴 issue in your code:
GitHub Actions step uses mutable version tag (v4) instead of a specific commit, allowing the action owner to silently update it to malicious code.
More details about this
The github/codeql-action/analyze@v4 action is pinned to a mutable tag (v4) rather than a specific commit hash. An attacker who gains control of the GitHub Actions repository could silently update the v4 tag to point to malicious code. When your workflow runs, it would automatically fetch and execute the attacker's version without any warning or visibility into what changed.
Here's how the attack would work:
- An attacker compromises the
codeql-actionrepository or its maintainer credentials - The attacker pushes malicious code and repoints the
v4tag to this new commit - On your next workflow run, the
uses: github/codeql-action/analyze@v4line fetches the malicious version - The malicious code runs with access to your repository secrets, source code, and CI environment
- The attacker could exfiltrate credentials, inject backdoors into your build artifacts, or compromise downstream users
This same attack pattern was used to compromise real projects like trivy-action and kics-github-action. The vulnerability exists because mutable tags like v4 can be repointed by the action maintainer at any time, and your workflow has no way to detect or prevent this.
To resolve this comment:
✨ Commit fix suggestion
- Replace
github/codeql-action/analyze@v4with a full 40-character commit SHA for the exactv4release you want to use, for bothanalyzesteps. - Keep the readable version in a comment next to the SHA so future updates are easier, for example:
uses: github/codeql-action/analyze@<full-40-char-sha> # v4.x.x. - Pin the matching
initstep the same way if it is still using@v4, so allgithub/codeql-actionsteps use immutable references consistently. - Get the correct SHA from the
github/codeql-actionrelease or tag page, and make sure it is the commit that thev4tag currently points to before updating the workflow. - Manually confirm the workflow still runs the same CodeQL action version after the change by checking the action reference shown in the workflow run. Pinning to a commit SHA prevents the action owner from silently moving a tag or branch to different code later.
💬 Ignore this finding
Reply with Semgrep commands to ignore this finding.
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by github-actions-mutable-action-tag.
You can view more details about this finding in the Semgrep AppSec Platform.
|
|
||
| - name: ⚙️ Initialize CodeQL | ||
| uses: github/codeql-action/init@v3 | ||
| uses: github/codeql-action/init@v4 |
There was a problem hiding this comment.
Semgrep identified a blocking 🔴 issue in your code:
GitHub Actions step references mutable version tag @v4 instead of a pinned commit SHA, allowing attackers to silently redirect the action to malicious code and steal repository secrets.
More details about this
The CodeQL action reference uses a mutable version tag (@v4) instead of a pinned commit SHA. An attacker who controls the github/codeql-action repository could silently update the v4 tag to point to malicious code, which would then execute in your workflow with access to your repository secrets and code.
Here's how this could be exploited:
- An attacker compromises the
github/codeql-actionrepository or gains control over thev4tag. - They push malicious code and repoint the
v4tag to a commit containing a backdoor that stealsGITHUB_TOKENor other secrets (stored insecrets.*). - Your workflow runs and automatically pulls the new malicious version at
github/codeql-action/init@v4. - The backdoor executes during the "⚙️ Initialize CodeQL" step, exfiltrating secrets or modifying your code before it gets built.
- An attacker could then use the stolen
GITHUB_TOKENto push malicious code to your repository or access other workflows.
Similarly, the github/codeql-action/analyze@v4 steps on lines below also use the mutable @v4 tag and face the same risk.
To resolve this comment:
✨ Commit fix suggestion
-
Replace the mutable ref in the CodeQL init step with a full 40-character commit SHA from the
github/codeql-actionrepository. Changeuses: github/codeql-action/init@v4touses: github/codeql-action/init@<full-40-character-sha>. -
Pin the matching CodeQL analyze steps the same way so the workflow uses one fixed action version consistently. Change
uses: github/codeql-action/analyze@v4touses: github/codeql-action/analyze@<same-release-full-40-character-sha>if both files come from the same release commit, or to the specific full SHA published for that action entrypoint. -
Keep the human-readable version in a comment so future updates are easier to track, for example:
uses: github/codeql-action/init@<full-40-character-sha> # v4.x.y. Pinning to a commit SHA prevents a tag likev4from being silently moved to different code later. -
Get the SHA from the official
github/codeql-actionrelease you want to trust, then copy that exact commit into the workflow instead of the tag. For example, use the commit shown for thev4release page or the action's commit URL, not a short SHA.
💬 Ignore this finding
Reply with Semgrep commands to ignore this finding.
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by github-actions-mutable-action-tag.
You can view more details about this finding in the Semgrep AppSec Platform.
Updates the requirements on actions/checkout, dtolnay/rust-toolchain, actions/upload-artifact, actions/setup-java, gradle/actions/setup-gradle, actions/download-artifact, docker/setup-qemu-action, docker/setup-buildx-action, docker/login-action, docker/metadata-action, docker/build-push-action, actions/setup-node, pnpm/action-setup, peter-evans/create-pull-request, dallay/common-actions/.github/workflows/cleanup-cache.yml, github/codeql-action, dallay/common-actions/.github/workflows/dependabot-auto-merge.yml, actions/dependency-review-action, actions/upload-pages-artifact, actions/deploy-pages, github/codeql-action/upload-sarif, actions/github-script, dallay/common-actions/.github/workflows/greetings.yml, actions/create-github-app-token, actions/cache, lycheeverse/lychee-action, actions/cache/save, google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml, google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml, dallay/common-actions/.github/workflows/pr-size-labeler.yml, codecov/codecov-action, googleapis/release-please-action, taiki-e/install-action, gradle/actions/dependency-submission, dallay/common-actions/.github/workflows/semantic-pull-request.yml, SonarSource/sonarqube-scan-action, SonarSource/sonarqube-quality-gate-action and dallay/common-actions/.github/workflows/stale.yml to permit the latest version.
Updates
actions/checkoutfrom 6.0.2 to 7.0.1Release notes
Sourced from actions/checkout's releases.
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
3d3c42eprep v7.0.1 release (#2531)2880268escape values passed to --unset (#2530)12cd223trim only ascii whitespace for branch (#2521)62661c4skip running unsafe pr check if input is default (#2518)e8d4307Bump the minor-actions-dependencies group with 2 updates (#2499)631c942eslint 9 (#2474)4f1f4aeBump actions/upload-artifact from 4 to 7 (#2476)ba09753Bump actions/checkout from 6 to 7 (#2488)b9e0990Bump docker/login-action from 3.3.0 to 4.2.0 (#2479)e8cb398Bump docker/build-push-action from 6.5.0 to 7.2.0 (#2478)Updates
dtolnay/rust-toolchainto d1031067263f94b142dd6c0ce24c5eb9d02d52a0Commits
Updates
actions/upload-artifactfrom 4.6.2 to 7.0.1Release notes
Sourced from actions/upload-artifact's releases.
... (truncated)
Commits
043fb46Merge pull request #797 from actions/yacaovsnc/update-dependency634250cInclude changes in typespec/ts-http-runtime 0.3.5e454baaReadme: bump all the example versions to v7 (#796)74fad66Update the readme with direct upload details (#795)bbbca2dSupport direct file uploads (#764)589182cUpgrade the module to ESM and bump dependencies (#762)47309c9Merge pull request #754 from actions/Link-/add-proxy-integration-tests02a8460Add proxy integration testb7c566aMerge pull request #745 from actions/upload-artifact-v6-releasee516bc8docs: correct description of Node.js 24 support in READMEUpdates
actions/setup-javafrom 5.2.0 to 6.0.1Release notes
Sourced from actions/setup-java's releases.
... (truncated)
Commits
de7274fAvoid macOS GPG socket overflow on long runner paths (#1266)134912aFix import-safe checks when scripts are run from a path with symlinks (#1265)0781fc6Fix alpine failures by switching default back to only warn on verification fa...4889c4aFix Temurin EA E2E signature verification (#1260)8fd3240[WIP] Fix failing GitHub Actions job for temurin 17 (#1259)2732291chore(deps-dev): update eslint and globals (#1256)1a8f22bchore: streamline Dependabot updates (#1255)85030b7docs: complete v6 release highlights (#1254)dd06d9cPrepare documentation for v6 release (#1253)59b3450chore(deps): combine open Dependabot npm updates (#1252)Updates
gradle/actions/setup-gradlefrom 5.0.2 to 6.3.0Release notes
Sourced from gradle/actions/setup-gradle's releases.
... (truncated)
Commits
9c97196Bump the github-actions group across 2 directories with 9 updates (#1024)760e4a4Bump the npm-dependencies group across 1 directory with 2 updates (#1037)73e4c42Update gradle-actions-caching library to v1.0.0 (#1029)a9d1438Add dependabot ignore rules for TypeScript 7.x and@types/node25.x/26.x68f3700[bot] Update dist directory5971332Bump Gradle Wrapper to 9.6.1, wrapper checksums, and Develocity plugin to 4.5...b5bc804[bot] Update dist directorydcbab4eBump npm-dependencies group with TypeScript 6.0.3,@types/node24.x, and secu...ca8d957Move non-smoke restore-gradle-home tests back to the integ-test suite (#1032)4318659[bot] Update dist directoryUpdates
actions/download-artifactfrom 7.0.0 to 8.0.1Release notes
Sourced from actions/download-artifact's releases.
Commits
3e5f45bAdd regression tests for CJK characters (#471)e6d03f6Add a regression test for artifact name + content-type mismatches (#472)70fc10cMerge pull request #461 from actions/danwkennedy/digest-mismatch-behaviorf258da9Add change docsccc058eFix linting issuesbd7976bAdd a setting to specify what to do on hash mismatch and default it toerrorac21fcfMerge pull request #460 from actions/danwkennedy/download-no-unzip15999bfAdd note about package bumps974686eBump the version tov8and add release notesfbe48b1Update test names to make it clearer what they doUpdates
docker/setup-qemu-actionfrom 3.7.0 to 4.3.0Release notes
Sourced from docker/setup-qemu-action's releases.
... (truncated)
Commits
1f40c72Merge pull request #336 from docker/dependabot/npm_and_yarn/docker/actions-to...932216e[dependabot skip] chore: update generated contenta39e895build(deps): bump@docker/actions-toolkitfrom 0.92.0 to 0.96.0a98ae9fMerge pull request #333 from docker/dependabot/npm_and_yarn/undici-6.28.08ebc9d1[dependabot skip] chore: update generated contentc41e3fcbuild(deps): bump undici from 6.27.0 to 6.28.05fc60dfMerge pull request #332 from docker/dependabot/npm_and_yarn/brace-expansion-1...a26e892Merge pull request #328 from docker/dependabot/github_actions/actions/checkou...aa6d042Merge pull request #324 from docker/dependabot/github_actions/actions/setup-n...d381ce5Merge pull request #317 from docker/dependabot/npm_and_yarn/sigstore-4.1.1Updates
docker/setup-buildx-actionfrom 3.12.0 to 4.3.0Release notes
Sourced from docker/setup-buildx-action's releases.