Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/staging.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ jobs:
uses: docker/setup-buildx-action@v4

- name: Login to Quay.io
uses: docker/login-action@v4
uses: docker/login-action@v4.5.1

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Semgrep identified an issue in your code:

GitHub Actions step uses mutable version tag v4.5.1 instead of a commit SHA, allowing the action owner to silently inject malicious code that could steal your repository secrets.

More details about this

The docker/login-action step is pinned to a mutable version tag (v4.5.1) instead of a specific commit SHA. This means the action maintainers can silently update the code at this tag without your knowledge.

Here's how an attacker could exploit this:

  1. Compromise the action repository: An attacker gains write access to the docker/login-action repository (e.g., through credential theft or social engineering).
  2. Modify the action code: They update the code at the v4.5.1 tag to include malicious logic—for example, exfiltrating the ${{ secrets.QUAY_ROBOT_TOKEN }} secret to an attacker-controlled server.
  3. Your workflow runs silently compromised: The next time your workflow runs after the tag is updated, it automatically pulls the poisoned action code. The step logs in to Quay.io as normal, but the secret is also sent to the attacker.
  4. Account takeover: With the leaked QUAY_ROBOT_TOKEN, the attacker can push malicious container images to your quay.io/wire/poll-app registry, compromising all deployments.

This attack pattern was used in real supply-chain compromises like trivy-action and kics-github-action. Version tags and branch names are mutable and can be repointed at any time by the action owner or a compromised maintainer.

To resolve this comment:

✨ Commit fix suggestion

Suggested change
uses: docker/login-action@v4.5.1
# Replace the SHA below with the full 40-character commit SHA for the trusted
# docker/login-action release you intend to use (ideally the commit for v4.5.1).
# This pins the action to an immutable revision to satisfy Semgrep.
uses: docker/login-action@0123456789abcdef0123456789abcdef01234567
View step-by-step instructions
  1. Replace the mutable action reference with a full 40-character commit SHA in the uses line for the login step.
    Change uses: docker/login-action@v4.5.1 to uses: docker/login-action@<full-40-character-commit-sha>.

  2. Keep the same action and version when choosing the SHA by using the commit that corresponds to the v4.5.1 release from the docker/login-action repository.
    This makes the workflow use an immutable revision instead of a tag that can be moved later.

  3. Update the step so it still looks like uses: docker/login-action@0123456789abcdef0123456789abcdef01234567, replacing the example SHA with the real 40-character commit for that release.

  4. Manually verify that the workflow can still authenticate to Quay.io and that the login step still receives registry, username, and password exactly as before.

Alternatively, if you need an immediate temporary fix and already trust a newer release, pin directly to that release’s full commit SHA instead of v4.5.1, but still avoid any tag such as @v4 or @v4.5.1.

💬 Ignore this finding

Reply with Semgrep commands to ignore this finding.

  • /fp <comment> for false positive
  • /ar <comment> for acceptable risk
  • /other <comment> for all other reasons

Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by github-actions-mutable-action-tag.

You can view more details about this finding in the Semgrep AppSec Platform.

with:
registry: ${{ env.REGISTRY }}
username: ${{ secrets.QUAY_USERNAME }}
Expand Down