actsense Security checks

Security checks

Every issue actsense looks for, what it means, and how to fix it. 79 checks across 8 categories, run against your workflows and every dependency they pull in.

17 critical 36 high 15 medium 11 low

79 of 79 checks

Severity shown is the highest a check can report.

Action Pinning & Immutability 8

High unpinned_version Unpinned Version Workflows that use actions with references that don't match standard pinning formats (version tags, commit SHAs, or branches) create security risks: unpinned or… Medium no_hash_pinning No Hash Pinning Workflows that pin actions to version tags (e.g., @v1, @v2.0.0) instead of commit SHAs are vulnerable to supply-chain attacks: tags are mutable—maintainers can move… Low short_hash_pinning Short Hash Pinning Workflows that pin actions to short commit SHAs (less than 40 characters) instead of full 40-character SHAs create ambiguity risks: short SHAs can collide with other… Medium older_action_version Older Action Version Workflows using older major versions of actions (v1, v2) when newer versions (v3+, v4+) are available expose themselves to known security vulnerabilities that have… Low inconsistent_action_version Inconsistent Action Version Using the same action with different versions across workflows means some jobs miss security patches while others get them. High unpinnable_docker_image Unpinnable Docker Image Docker actions that use mutable tags (e.g., latest, v1, v1.2) instead of immutable digests create supply-chain risks: tags can be moved to point to different images,… High unpinnable_composite_subaction Unpinnable Composite Subaction Composite actions that use sub-actions with tags or branches instead of commit SHAs create transitive dependency risks: tags and branches can be moved or updated,… High unpinned_javascript_resources Unpinned Javascript Resources JavaScript actions that download external resources (scripts, binaries, archives) without checksum verification create supply-chain security risks: downloaded…

Permissions & Access Control 7

Secrets & Credentials 13

Critical potential_hardcoded_secret Potential Hardcoded Secret Workflows containing hardcoded secrets (passwords, API keys, tokens, database credentials) expose those credentials to anyone with read access to the repository. Critical potential_hardcoded_cloud_credentials Potential Hardcoded Cloud Credentials Workflows that contain hardcoded cloud credentials (AWS keys, Azure secrets, GCP service account keys) in run commands expose those credentials to anyone with read… High long_term_cloud_credentials Long Term Cloud Credentials Storing static cloud provider credentials (AWS, Azure, or GCP) in GitHub secrets means the keys never expire. High secret_in_environment Secret In Environment Workflows that expose secrets directly in environment variables create security risks: environment variables may be logged by actions or tools, visible in workflow… Medium secrets_access_untrusted Secrets Access Untrusted Workflows that pass secrets to untrusted third-party actions create extreme supply-chain risks: untrusted actions may be malicious, compromised, or contain… Critical secrets_in_matrix Secrets In Matrix Workflows that include secrets in matrix strategy definitions expose those secrets to ALL matrix job combinations: each matrix job can access and potentially log the… Medium environment_with_secrets Environment With Secrets GitHub environments act as secret vaults plus deployment gates, but if you attach an environment to a job without configuring protection rules, any workflow with… High excessive_secret_exposure Excessive Secret Exposure The secrets context can be serialized in bulk with the toJson(secrets) expression. Medium secrets_inherit Reusable Workflow Secrets Inheritance When one workflow calls a reusable workflow, it can forward credentials with secrets: inherit. Medium secrets_outside_env Secrets Used Outside Environment Variables Interpolating a secret directly into a run: command — deploy --token ${{ secrets.TOKEN }} — places the plaintext value on the command line, where it can leak through… High hardcoded_container_credentials Hardcoded Container Credentials Jobs can run inside a container or spin up service containers that pull from a private registry, authenticating with container.credentials / services..credentials. Critical – High trufflehog_secret_detected Secret Detected by TruffleHog TruffleHog matched a known credential format (a cloud key, API token, private key, etc.) in the workflow file. Low optional_secret_input Optional Secret Input An action declares an input whose description says it carries a secret, password, or token, but marks it required: false with no default.

Workflow Security 15

High – Medium dangerous_event Dangerous Event GitHub Actions runs workflow code from trusted workflow definitions on the default branch for most events. Critical – High insecure_pull_request_target Insecure Pull Request Target pullrequesttarget runs with the base repository’s token (Usually write). High – Medium unsafe_checkout Unsafe Checkout Workflows that use actions/checkout with persist-credentials: true create security risks: credentials are stored in the runner's Git configuration, subsequent steps… Medium unsafe_checkout_ref Unsafe Checkout Ref Workflows that use actions/checkout with refs containing variables that may not be properly validated create security risks: if the ref comes from user input… Low checkout_full_history Checkout Full History Setting actions/checkout to fetch-depth: 0 clones the entire repository history into the runner. Critical script_injection Script Injection Workflows that use user-controlled input in dangerous PowerShell operations (Invoke-Expression, Invoke-Command, call operators) are vulnerable to script injection:… Critical – High shell_injection Shell Injection Workflows that pipe user-controlled input directly to shell interpreters (bash, sh, zsh) without validation create code injection vulnerabilities: attackers can… Critical – Low risky_context_usage Risky Context Usage Workflows that use user-controllable GitHub context variables (such as github.event.issue.body, github.event.pullrequest.title, github.refname, etc.) create injection… Critical github_env_injection GitHub Environment File Injection GitHub Actions exposes the special files $GITHUBENV and $GITHUBPATH so that a step can set environment variables and prepend directories to PATH for subsequent steps… High github_output_injection GitHub Output File Injection A step can publish outputs to later steps and jobs by appending key=value lines to the special $GITHUBOUTPUT file. High insecure_commands Insecure Workflow Commands GitHub Actions once let steps set environment variables and modify PATH by printing ::set-env and ::add-path stdout commands. Medium spoofable_actor_condition Spoofable Actor Condition Workflows sometimes gate privileged behaviour on the actor context — for example if: github.actor == 'dependabot[bot]' — to "only run for a trusted user or bot." The… High – Medium code_injection_via_input Code Injection via Input Workflows that accept workflowdispatch inputs and interpolate them directly into shell commands give untrusted users a remote code execution primitive: an attacker… Medium unvalidated_workflow_input Unvalidated Workflow Input Workflows with workflowdispatch inputs that are optional or used in shell commands without validation create security risks: optional inputs may be used without… Medium unsafe_shell Unsafe Shell A step that runs Bash without exit-on-error keeps going after a command fails.

Supply Chain Security 14

High – Medium untrusted_action_source Untrusted Action Source Workflows that use actions from untrusted third-party publishers create supply-chain security risks: actions can contain malicious code, run with your workflow's… High untrusted_action_unpinned Untrusted Action Unpinned Untrusted third-party actions that are not pinned to a specific version create critical security risks: the action can be updated by the maintainer at any time,… High typosquatting_action Typosquatting Action Workflows using actions with suspicious naming patterns (similar to popular actions but with slight variations) may be victims of typosquatting attacks: attackers… Medium deprecated_action Deprecated Action Running outdated versions of community actions leaves workflows exposed to known vulnerabilities—GitHub often revs v1 actions multiple times to address security flaws. Critical missing_action_repository Missing Action Repository Workflows that reference actions from repositories that don't exist or are inaccessible will fail at runtime, disrupting CI/CD pipelines and potentially causing… Medium ref_version_mismatch Action Ref / Version Comment Mismatch Pinning an action to a full commit SHA is the most secure way to reference it, and the common convention is to annotate the SHA with the human-readable version it… High unpinned_dockerfile_dependencies Unpinned Dockerfile Dependencies Docker actions with Dockerfiles that install Python packages (or other dependencies) without version pinning create security and reproducibility risks: package… High unpinned_dockerfile_resources Unpinned Dockerfile Resources Docker actions with Dockerfiles that download external resources (scripts, binaries, archives) without checksum verification create security risks: downloaded… High unpinned_external_resources Unpinned External Resources Composite actions that download external resources (scripts, binaries, archives) without checksum verification create security risks: downloaded resources can be… High unpinned_javascript_resources Unpinned Javascript Resources JavaScript actions that download external resources (scripts, binaries, archives) without checksum verification create supply-chain security risks: downloaded… High unpinned_npm_packages Unpinned Npm Packages Workflows and composite actions that install NPM packages without version locking create security and reproducibility risks: package versions can change between runs,… High unpinned_python_packages Unpinned Python Packages Workflows and composite actions that install Python packages without version pinning create security and reproducibility risks: package versions can change between… Low unfiltered_network_traffic Unfiltered Network Traffic Workflows that perform network operations (curl, wget, ssh, etc.) without filtering or monitoring create security risks: network traffic can be used to exfiltrate… Low no_file_tampering_protection No File Tampering Protection Build jobs that modify files during execution without integrity checks are vulnerable to supply-chain tampering: malicious actions or compromised dependencies can…

Self-Hosted Runners 9

Low self_hosted_runner Self Hosted Runner Workflows using self-hosted runners pose significant security risks compared to GitHub-hosted runners: self-hosted runners have persistent access to your… Critical self_hosted_runner_pr_exposure Self Hosted Runner Pr Exposure Self-hosted runners exposed to pull requests in public repositories create extreme security risks: attackers from forks can create PRs that trigger workflows on your… High self_hosted_runner_issue_exposure Self Hosted Runner Issue Exposure Self-hosted runners that can be triggered by issue events in public repositories create significant security risks: anyone can create issues in public repositories,… Critical self_hosted_runner_write_all Self Hosted Runner Write All Self-hosted runners with write-all permissions create extreme security risks: write-all grants excessive access to repository resources, and if the runner is… High self_hosted_runner_secrets_in_run Self Hosted Runner Secrets In Run Workflows that use secrets directly in run commands on self-hosted runners expose those secrets to process lists, shell history, and logs: secrets may be visible in… High self_hosted_runner_network_risk Self Hosted Runner Network Risk Self-hosted runners that download and execute code from the internet without verification create significant security risks: downloaded scripts may be malicious,… High runner_label_confusion Runner Label Confusion Workflows using runner labels that are confusing or similar to GitHub-hosted runner labels (e.g., ubuntu-latest, windows-latest, self-hosted-ubuntu) create security… Critical public_repo_self_hosted_secrets Public Repo Self Hosted Secrets Self-hosted runners in public repositories that have access to secrets create extreme security risks: public repos are accessible to anyone, so attackers can analyze… High public_repo_self_hosted_environment Public Repo Self Hosted Environment Self-hosted runners in public repositories that access protected environments create significant security risks: public repos are accessible to anyone, so attackers…

Best Practices 7

Advanced Threats 6