chore(deps): bump the github-actions group with 38 updates - #900
chore(deps): bump the github-actions group with 38 updates#900dependabot[bot] wants to merge 1 commit into
Conversation
Updates the requirements on [actions/checkout](https://github.com/actions/checkout), [dtolnay/rust-toolchain](https://github.com/dtolnay/rust-toolchain), [actions/upload-artifact](https://github.com/actions/upload-artifact), [actions/setup-java](https://github.com/actions/setup-java), [gradle/actions/setup-gradle](https://github.com/gradle/actions), [actions/download-artifact](https://github.com/actions/download-artifact), [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action), [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action), [docker/login-action](https://github.com/docker/login-action), [docker/metadata-action](https://github.com/docker/metadata-action), [docker/build-push-action](https://github.com/docker/build-push-action), [actions/setup-node](https://github.com/actions/setup-node), [pnpm/action-setup](https://github.com/pnpm/action-setup), [peter-evans/create-pull-request](https://github.com/peter-evans/create-pull-request), [dallay/common-actions/.github/workflows/cleanup-cache.yml](https://github.com/dallay/common-actions), [github/codeql-action](https://github.com/github/codeql-action), [dallay/common-actions/.github/workflows/dependabot-auto-merge.yml](https://github.com/dallay/common-actions), [actions/dependency-review-action](https://github.com/actions/dependency-review-action), [actions/upload-pages-artifact](https://github.com/actions/upload-pages-artifact), [actions/deploy-pages](https://github.com/actions/deploy-pages), [github/codeql-action/upload-sarif](https://github.com/github/codeql-action), [actions/github-script](https://github.com/actions/github-script), [dallay/common-actions/.github/workflows/greetings.yml](https://github.com/dallay/common-actions), [actions/create-github-app-token](https://github.com/actions/create-github-app-token), [actions/cache](https://github.com/actions/cache), [lycheeverse/lychee-action](https://github.com/lycheeverse/lychee-action), [actions/cache/save](https://github.com/actions/cache), [google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml](https://github.com/google/osv-scanner-action), [google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml](https://github.com/google/osv-scanner-action), [dallay/common-actions/.github/workflows/pr-size-labeler.yml](https://github.com/dallay/common-actions), [codecov/codecov-action](https://github.com/codecov/codecov-action), [googleapis/release-please-action](https://github.com/googleapis/release-please-action), [taiki-e/install-action](https://github.com/taiki-e/install-action), [gradle/actions/dependency-submission](https://github.com/gradle/actions), [dallay/common-actions/.github/workflows/semantic-pull-request.yml](https://github.com/dallay/common-actions), [SonarSource/sonarqube-scan-action](https://github.com/sonarsource/sonarqube-scan-action), [SonarSource/sonarqube-quality-gate-action](https://github.com/sonarsource/sonarqube-quality-gate-action) and [dallay/common-actions/.github/workflows/stale.yml](https://github.com/dallay/common-actions) to permit the latest version. Updates `actions/checkout` from 6.0.2 to 7.0.1 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@de0fac2...3d3c42e) Updates `dtolnay/rust-toolchain` to 6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 - [Release notes](https://github.com/dtolnay/rust-toolchain/releases) - [Commits](https://github.com/dtolnay/rust-toolchain/commits/6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772) Updates `actions/upload-artifact` from 4.6.2 to 7.0.1 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@ea165f8...043fb46) Updates `actions/setup-java` from 5.2.0 to 6.0.0 - [Release notes](https://github.com/actions/setup-java/releases) - [Commits](actions/setup-java@be666c2...dd06d9c) Updates `gradle/actions/setup-gradle` from 5.0.2 to 6.3.0 - [Release notes](https://github.com/gradle/actions/releases) - [Commits](gradle/actions@0723195...9c97196) Updates `actions/download-artifact` from 7.0.0 to 8.0.1 - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](actions/download-artifact@37930b1...3e5f45b) Updates `docker/setup-qemu-action` from 3.7.0 to 4.2.0 - [Release notes](https://github.com/docker/setup-qemu-action/releases) - [Commits](docker/setup-qemu-action@c7c5346...96fe6ef) Updates `docker/setup-buildx-action` from 3.12.0 to 4.3.0 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](docker/setup-buildx-action@8d2750c...37fe631) Updates `docker/login-action` from 3.7.0 to 4.6.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@c94ce9f...dbcb813) Updates `docker/metadata-action` from 5.10.0 to 6.2.0 - [Release notes](https://github.com/docker/metadata-action/releases) - [Commits](docker/metadata-action@c299e40...dc80280) Updates `docker/build-push-action` from 6.19.2 to 7.3.0 - [Release notes](https://github.com/docker/build-push-action/releases) - [Commits](docker/build-push-action@10e90e3...53b7df9) Updates `actions/setup-node` from 6.3.0 to 7.0.0 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@53b8394...8207627) Updates `pnpm/action-setup` from 4.2.0 to 6.0.10 - [Release notes](https://github.com/pnpm/action-setup/releases) - [Commits](pnpm/action-setup@41ff726...0977fd9) Updates `peter-evans/create-pull-request` from 8.0.0 to 8.1.1 - [Release notes](https://github.com/peter-evans/create-pull-request/releases) - [Commits](peter-evans/create-pull-request@98357b1...5f6978f) Updates `dallay/common-actions/.github/workflows/cleanup-cache.yml` from 2.0.0 to 2.2.4 - [Release notes](https://github.com/dallay/common-actions/releases) - [Commits](dallay/common-actions@6ecd716...6906025) Updates `github/codeql-action` from 3 to 4 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@v3...v4) Updates `dallay/common-actions/.github/workflows/dependabot-auto-merge.yml` from 2.0.0 to 2.2.4 - [Release notes](https://github.com/dallay/common-actions/releases) - [Commits](dallay/common-actions@v2.0.0...v2.2.4) Updates `actions/dependency-review-action` from 4.8.3 to 5.0.0 - [Release notes](https://github.com/actions/dependency-review-action/releases) - [Commits](actions/dependency-review-action@05fe457...a1d282b) Updates `actions/upload-pages-artifact` from 4.0.0 to 5.0.0 - [Release notes](https://github.com/actions/upload-pages-artifact/releases) - [Commits](actions/upload-pages-artifact@7b1f4a7...fc324d3) Updates `actions/deploy-pages` from 4.0.5 to 5.0.0 - [Release notes](https://github.com/actions/deploy-pages/releases) - [Commits](actions/deploy-pages@d6db901...cd2ce8f) Updates `github/codeql-action/upload-sarif` from 4.31.10 to 4.37.9 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@cdefb33...cdf488f) Updates `actions/github-script` from 8.0.0 to 9.0.0 - [Release notes](https://github.com/actions/github-script/releases) - [Commits](actions/github-script@ed59741...3a2844b) Updates `dallay/common-actions/.github/workflows/greetings.yml` from 2.0.0 to 2.2.4 - [Release notes](https://github.com/dallay/common-actions/releases) - [Commits](dallay/common-actions@6ecd716...6906025) Updates `actions/create-github-app-token` from 2.2.1 to 3.2.0 - [Release notes](https://github.com/actions/create-github-app-token/releases) - [Changelog](https://github.com/actions/create-github-app-token/blob/main/CHANGELOG.md) - [Commits](actions/create-github-app-token@v2.2.1...bcd2ba4) Updates `actions/cache` from 4.2.1 to 6.1.0 - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@0c907a7...55cc834) Updates `lycheeverse/lychee-action` from 2.8.0 to 2.9.0 - [Release notes](https://github.com/lycheeverse/lychee-action/releases) - [Commits](lycheeverse/lychee-action@8646ba3...e747777) Updates `actions/cache/save` from 4.2.1 to 6.1.0 - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@0c907a7...55cc834) Updates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml` from eb5b619bb565d10623076caba5263750fde3c790 to ffa0a5f39214d80778c9b494822d94d0d9668458 - [Release notes](https://github.com/google/osv-scanner-action/releases) - [Commits](google/osv-scanner-action@eb5b619...ffa0a5f) Updates `google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml` from eb5b619bb565d10623076caba5263750fde3c790 to ffa0a5f39214d80778c9b494822d94d0d9668458 - [Release notes](https://github.com/google/osv-scanner-action/releases) - [Commits](google/osv-scanner-action@eb5b619...ffa0a5f) Updates `dallay/common-actions/.github/workflows/pr-size-labeler.yml` from 2.0.0 to 2.2.4 - [Release notes](https://github.com/dallay/common-actions/releases) - [Commits](dallay/common-actions@6ecd716...6906025) Updates `codecov/codecov-action` from 5.5.3 to 7.0.0 - [Release notes](https://github.com/codecov/codecov-action/releases) - [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md) - [Commits](codecov/codecov-action@1af5884...fb8b358) Updates `googleapis/release-please-action` from 4.4.0 to 5.0.0 - [Release notes](https://github.com/googleapis/release-please-action/releases) - [Changelog](https://github.com/googleapis/release-please-action/blob/main/CHANGELOG.md) - [Commits](googleapis/release-please-action@16a9c90...45996ed) Updates `taiki-e/install-action` from 2.68.14 to 2.86.8 - [Release notes](https://github.com/taiki-e/install-action/releases) - [Commits](taiki-e/install-action@v2.68.14...v2.86.8) Updates `gradle/actions/dependency-submission` from 5.0.2 to 6.3.0 - [Release notes](https://github.com/gradle/actions/releases) - [Commits](gradle/actions@0723195...9c97196) Updates `dallay/common-actions/.github/workflows/semantic-pull-request.yml` from 2.0.0 to 2.2.4 - [Release notes](https://github.com/dallay/common-actions/releases) - [Commits](dallay/common-actions@v2.0.0...v2.2.4) Updates `SonarSource/sonarqube-scan-action` from 6.0.0 to 8.2.1 - [Release notes](https://github.com/sonarsource/sonarqube-scan-action/releases) - [Commits](SonarSource/sonarqube-scan-action@fd88b7d...2291811) Updates `SonarSource/sonarqube-quality-gate-action` from 1.1.0 to 1.2.1 - [Release notes](https://github.com/sonarsource/sonarqube-quality-gate-action/releases) - [Commits](SonarSource/sonarqube-quality-gate-action@d304d05...7a5fffe) Updates `dallay/common-actions/.github/workflows/stale.yml` from 2.0.0 to 2.2.4 - [Release notes](https://github.com/dallay/common-actions/releases) - [Commits](dallay/common-actions@6ecd716...6906025) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: dtolnay/rust-toolchain dependency-version: 6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 dependency-type: direct:production dependency-group: github-actions - dependency-name: actions/upload-artifact dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/setup-java dependency-version: 6.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: gradle/actions/setup-gradle dependency-version: 6.3.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/download-artifact dependency-version: 8.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: docker/setup-qemu-action dependency-version: 4.2.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: docker/setup-buildx-action dependency-version: 4.3.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: docker/login-action dependency-version: 4.6.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: docker/metadata-action dependency-version: 6.2.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: docker/build-push-action dependency-version: 7.3.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/setup-node dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: pnpm/action-setup dependency-version: 6.0.10 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: peter-evans/create-pull-request dependency-version: 8.1.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: dallay/common-actions/.github/workflows/cleanup-cache.yml dependency-version: 2.2.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: github/codeql-action dependency-version: '4' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: dallay/common-actions/.github/workflows/dependabot-auto-merge.yml dependency-version: 2.2.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/dependency-review-action dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/upload-pages-artifact dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/deploy-pages dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.37.9 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/github-script dependency-version: 9.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: dallay/common-actions/.github/workflows/greetings.yml dependency-version: 2.2.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/create-github-app-token dependency-version: 3.2.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/cache dependency-version: 6.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: lycheeverse/lychee-action dependency-version: 2.9.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/cache/save dependency-version: 6.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml dependency-version: ffa0a5f39214d80778c9b494822d94d0d9668458 dependency-type: direct:production dependency-group: github-actions - dependency-name: google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml dependency-version: ffa0a5f39214d80778c9b494822d94d0d9668458 dependency-type: direct:production dependency-group: github-actions - dependency-name: dallay/common-actions/.github/workflows/pr-size-labeler.yml dependency-version: 2.2.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: codecov/codecov-action dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: googleapis/release-please-action dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: taiki-e/install-action dependency-version: 2.86.8 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: gradle/actions/dependency-submission dependency-version: 6.3.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: dallay/common-actions/.github/workflows/semantic-pull-request.yml dependency-version: 2.2.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: SonarSource/sonarqube-scan-action dependency-version: 8.2.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: SonarSource/sonarqube-quality-gate-action dependency-version: 1.2.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: dallay/common-actions/.github/workflows/stale.yml dependency-version: 2.2.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
|
It seems you edited the limitation files. These files aren't open for contributions. If you think they should be, feel free to reply here. |
|
Thank you for contributing to this project with this PR, welcome to the community and the amazing world of open source! |
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
| if: > | ||
| steps.gradle_build_java_kotlin.outcome == 'success' | ||
| uses: github/codeql-action/analyze@v3 | ||
| uses: github/codeql-action/analyze@v4 |
There was a problem hiding this comment.
Semgrep identified a blocking 🔴 issue in your code:
GitHub Actions step uses mutable version tag (v4) instead of a specific commit, allowing the action owner to silently update it to malicious code.
More details about this
The github/codeql-action/analyze@v4 action is pinned to a mutable tag (v4) rather than a specific commit hash. An attacker who gains control of the GitHub Actions repository could silently update the v4 tag to point to malicious code. When your workflow runs, it would automatically fetch and execute the attacker's version without any warning or visibility into what changed.
Here's how the attack would work:
- An attacker compromises the
codeql-actionrepository or its maintainer credentials - The attacker pushes malicious code and repoints the
v4tag to this new commit - On your next workflow run, the
uses: github/codeql-action/analyze@v4line fetches the malicious version - The malicious code runs with access to your repository secrets, source code, and CI environment
- The attacker could exfiltrate credentials, inject backdoors into your build artifacts, or compromise downstream users
This same attack pattern was used to compromise real projects like trivy-action and kics-github-action. The vulnerability exists because mutable tags like v4 can be repointed by the action maintainer at any time, and your workflow has no way to detect or prevent this.
To resolve this comment:
✨ Commit fix suggestion
- Replace
github/codeql-action/analyze@v4with a full 40-character commit SHA for the exactv4release you want to use, for bothanalyzesteps. - Keep the readable version in a comment next to the SHA so future updates are easier, for example:
uses: github/codeql-action/analyze@<full-40-char-sha> # v4.x.x. - Pin the matching
initstep the same way if it is still using@v4, so allgithub/codeql-actionsteps use immutable references consistently. - Get the correct SHA from the
github/codeql-actionrelease or tag page, and make sure it is the commit that thev4tag currently points to before updating the workflow. - Manually confirm the workflow still runs the same CodeQL action version after the change by checking the action reference shown in the workflow run. Pinning to a commit SHA prevents the action owner from silently moving a tag or branch to different code later.
💬 Ignore this finding
Reply with Semgrep commands to ignore this finding.
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by github-actions-mutable-action-tag.
You can view more details about this finding in the Semgrep AppSec Platform.
|
|
||
| - name: ⚙️ Initialize CodeQL | ||
| uses: github/codeql-action/init@v3 | ||
| uses: github/codeql-action/init@v4 |
There was a problem hiding this comment.
Semgrep identified a blocking 🔴 issue in your code:
GitHub Actions step references mutable version tag @v4 instead of a pinned commit SHA, allowing attackers to silently redirect the action to malicious code and steal repository secrets.
More details about this
The CodeQL action reference uses a mutable version tag (@v4) instead of a pinned commit SHA. An attacker who controls the github/codeql-action repository could silently update the v4 tag to point to malicious code, which would then execute in your workflow with access to your repository secrets and code.
Here's how this could be exploited:
- An attacker compromises the
github/codeql-actionrepository or gains control over thev4tag. - They push malicious code and repoint the
v4tag to a commit containing a backdoor that stealsGITHUB_TOKENor other secrets (stored insecrets.*). - Your workflow runs and automatically pulls the new malicious version at
github/codeql-action/init@v4. - The backdoor executes during the "⚙️ Initialize CodeQL" step, exfiltrating secrets or modifying your code before it gets built.
- An attacker could then use the stolen
GITHUB_TOKENto push malicious code to your repository or access other workflows.
Similarly, the github/codeql-action/analyze@v4 steps on lines below also use the mutable @v4 tag and face the same risk.
To resolve this comment:
✨ Commit fix suggestion
-
Replace the mutable ref in the CodeQL init step with a full 40-character commit SHA from the
github/codeql-actionrepository. Changeuses: github/codeql-action/init@v4touses: github/codeql-action/init@<full-40-character-sha>. -
Pin the matching CodeQL analyze steps the same way so the workflow uses one fixed action version consistently. Change
uses: github/codeql-action/analyze@v4touses: github/codeql-action/analyze@<same-release-full-40-character-sha>if both files come from the same release commit, or to the specific full SHA published for that action entrypoint. -
Keep the human-readable version in a comment so future updates are easier to track, for example:
uses: github/codeql-action/init@<full-40-character-sha> # v4.x.y. Pinning to a commit SHA prevents a tag likev4from being silently moved to different code later. -
Get the SHA from the official
github/codeql-actionrelease you want to trust, then copy that exact commit into the workflow instead of the tag. For example, use the commit shown for thev4release page or the action's commit URL, not a short SHA.
💬 Ignore this finding
Reply with Semgrep commands to ignore this finding.
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by github-actions-mutable-action-tag.
You can view more details about this finding in the Semgrep AppSec Platform.
| - name: 🔍 Run CodeQL Analysis | ||
| if: matrix.language != 'java-kotlin' | ||
| uses: github/codeql-action/analyze@v3 | ||
| uses: github/codeql-action/analyze@v4 |
There was a problem hiding this comment.
Semgrep identified a blocking 🔴 issue in your code:
GitHub Actions step uses mutable tag @v4 instead of a pinned commit SHA, allowing the action owner to silently redirect to malicious code and compromise your CI/CD pipeline.
More details about this
The GitHub Actions workflow is using uses: github/codeql-action/analyze@v4, which pins to a mutable tag (v4) rather than a specific commit SHA. This means the action owner can silently redirect what code runs in your workflow without your knowledge.
Here's how an attacker could exploit this:
-
Compromise the codeql-action repository: An attacker gains write access to the GitHub repository hosting
github/codeql-action(or tricks GitHub into transferring ownership). -
Repoint the
v4tag: The attacker updates thev4tag to point to a malicious commit they've created that includes backdoored code (e.g., code that exfiltrates secrets from the GitHub Actions environment). -
Your workflow silently runs the backdoor: The next time your workflow runs, GitHub Actions resolves
@v4to the attacker's malicious commit. Youranalyzestep now runs arbitrary code with access tosecretsand repository data. -
Extract sensitive data: The malicious
github/codeql-action/analyzecould steal environment variables containing API keys, access tokens, or commit credentials that were set up for your repository.
This has happened in the real world—the trivy-action and kics-github-action projects both experienced compromises where tags were repointed to inject malicious code into CI/CD pipelines.
To resolve this comment:
✨ Commit fix suggestion
- Replace the mutable reference
github/codeql-action/analyze@v4with a full 40-character commit SHA for thev4release, for examplegithub/codeql-action/analyze@<full-40-character-sha>. - Update both
uses: github/codeql-action/analyze@v4entries in this workflow so they point to the same pinned commit SHA. - Get the correct SHA from the
github/codeql-actionrepository’sv4release or tags page, and use the exact commit value instead of the tag name. This prevents the action from changing silently if the tag is moved. - Keep the action name and step conditions the same; only change the part after
@, for exampleuses: github/codeql-action/analyze@8ade135a41bc03ea155e62e844d188df1ea18608.
💬 Ignore this finding
Reply with Semgrep commands to ignore this finding.
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by github-actions-mutable-action-tag.
You can view more details about this finding in the Semgrep AppSec Platform.
Updates the requirements on actions/checkout, dtolnay/rust-toolchain, actions/upload-artifact, actions/setup-java, gradle/actions/setup-gradle, actions/download-artifact, docker/setup-qemu-action, docker/setup-buildx-action, docker/login-action, docker/metadata-action, docker/build-push-action, actions/setup-node, pnpm/action-setup, peter-evans/create-pull-request, dallay/common-actions/.github/workflows/cleanup-cache.yml, github/codeql-action, dallay/common-actions/.github/workflows/dependabot-auto-merge.yml, actions/dependency-review-action, actions/upload-pages-artifact, actions/deploy-pages, github/codeql-action/upload-sarif, actions/github-script, dallay/common-actions/.github/workflows/greetings.yml, actions/create-github-app-token, actions/cache, lycheeverse/lychee-action, actions/cache/save, google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml, google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml, dallay/common-actions/.github/workflows/pr-size-labeler.yml, codecov/codecov-action, googleapis/release-please-action, taiki-e/install-action, gradle/actions/dependency-submission, dallay/common-actions/.github/workflows/semantic-pull-request.yml, SonarSource/sonarqube-scan-action, SonarSource/sonarqube-quality-gate-action and dallay/common-actions/.github/workflows/stale.yml to permit the latest version.
Updates
actions/checkoutfrom 6.0.2 to 7.0.1Release notes
Sourced from actions/checkout's releases.
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
3d3c42eprep v7.0.1 release (#2531)2880268escape values passed to --unset (#2530)12cd223trim only ascii whitespace for branch (#2521)62661c4skip running unsafe pr check if input is default (#2518)e8d4307Bump the minor-actions-dependencies group with 2 updates (#2499)631c942eslint 9 (#2474)4f1f4aeBump actions/upload-artifact from 4 to 7 (#2476)ba09753Bump actions/checkout from 6 to 7 (#2488)b9e0990Bump docker/login-action from 3.3.0 to 4.2.0 (#2479)e8cb398Bump docker/build-push-action from 6.5.0 to 7.2.0 (#2478)Updates
dtolnay/rust-toolchainto 6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772Commits
Updates
actions/upload-artifactfrom 4.6.2 to 7.0.1Release notes
Sourced from actions/upload-artifact's releases.
... (truncated)
Commits
043fb46Merge pull request #797 from actions/yacaovsnc/update-dependency634250cInclude changes in typespec/ts-http-runtime 0.3.5e454baaReadme: bump all the example versions to v7 (#796)74fad66Update the readme with direct upload details (#795)bbbca2dSupport direct file uploads (#764)589182cUpgrade the module to ESM and bump dependencies (#762)47309c9Merge pull request #754 from actions/Link-/add-proxy-integration-tests02a8460Add proxy integration testb7c566aMerge pull request #745 from actions/upload-artifact-v6-releasee516bc8docs: correct description of Node.js 24 support in READMEUpdates
actions/setup-javafrom 5.2.0 to 6.0.0Release notes
Sourced from actions/setup-java's releases.
... (truncated)
Commits
dd06d9cPrepare documentation for v6 release (#1253)59b3450chore(deps): combine open Dependabot npm updates (#1252)b96213dSet default signature verification for supported distributions (#1246)1dbac3cdocs: expose contributing guide to GitHub (#1245)11741d6ci: constrain cache e2e job modes (#1244)ff99aa1Fix Oracle macOS E2E version (#1243)416c6d1Add Red Hat Build of OpenJDK support (#1241)5f75b27Add Maven dependency-resolution repositories (#1240)a42a52cAdd multiple Maven server credentials (#1239)fb4abd7test: cover JDK 26 from SDKMAN (#1238)Updates
gradle/actions/setup-gradlefrom 5.0.2 to 6.3.0Release notes
Sourced from gradle/actions/setup-gradle's releases.
... (truncated)
Commits
9c97196Bump the github-actions group across 2 directories with 9 updates (#1024)760e4a4Bump the npm-dependencies group across 1 directory with 2 updates (#1037)73e4c42Update gradle-actions-caching library to v1.0.0 (#1029)a9d1438Add dependabot ignore rules for TypeScript 7.x and@types/node25.x/26.x68f3700[bot] Update dist directory5971332Bump Gradle Wrapper to 9.6.1, wrapper checksums, and Develocity plugin to 4.5...b5bc804[bot] Update dist directorydcbab4eBump npm-dependencies group with TypeScript 6.0.3,@types/node24.x, and secu...ca8d957Move non-smoke restore-gradle-home tests back to the integ-test suite (#1032)4318659[bot] Update dist directoryUpdates
actions/download-artifactfrom 7.0.0 to 8.0.1Release notes
Sourced from actions/download-artifact's releases.
Commits
3e5f45bAdd regression tests for CJK characters (#471)e6d03f6Add a regression test for artifact name + content-type mismatches (#472)70fc10cMerge pull request #461 from actions/danwkennedy/digest-mismatch-behaviorf258da9Add change docsccc058eFix linting issuesbd7976bAdd a setting to specify what to do on hash mismatch and default it toerrorac21fcfMerge pull request #460 from actions/danwkennedy/download-no-unzip15999bfAdd note about package bumps974686eBump the version tov8and add release notesfbe48b1Update test names to make it clearer what they doUpdates
docker/setup-qemu-actionfrom 3.7.0 to 4.2.0Release notes
Sourced from docker/setup-qemu-action's releases.
Commits
96fe6efMerge pull request #315 from docker/dependabot/npm_and_yarn/docker/actions-to...31f08d3[dependabot skip] chore: update generated content4e7017abuild(deps): bump@docker/actions-toolkitfrom 0.91.0 to 0.92.00eca235Merge pull request #314 from crazy-max/fix-yarn-preapprove-actions-toolkitea66a41chore: allow actions-toolkit to bypass yarn age gate451542bMerge pull request #308 from docker/dependabot/npm_and_yarn/undici-6.27.0532ae00[dependabot skip] chore: update generated contentb6f5af6build(deps): bump undici from 6.26.0 to 6.27.0cf96b86Merge pull request #304 from docker/dependabot/npm_and_yarn/tmp-0.2.7f0ba643[dependabot skip] chore: update generated contentUpdates
docker/setup-buildx-actionfrom 3.12.0 to 4.3.0Release notes
Sourced from docker/setup-buildx-action's releases.