Skip to content

Fix possible this workflow uses secrets: inherit to pass all of the calling workflow's s… in build-docker.ym - #1437

Open
begininvoke wants to merge 1 commit into
zedeus:masterfrom
begininvoke:redgem/security-fix-ccad0361
Open

Fix possible this workflow uses secrets: inherit to pass all of the calling workflow's s… in build-docker.ym#1437
begininvoke wants to merge 1 commit into
zedeus:masterfrom
begininvoke:redgem/security-fix-ccad0361

Conversation

@begininvoke

Copy link
Copy Markdown

Small change to .github/workflows/build-docker.yml — a scan flagged the code below and it looked genuine. It is around line 20.

The workflow forwards all repository secrets to a reusable workflow using secrets: inherit. This grants the called workflow unnecessary privileged access; if the reusable workflow is compromised or originates from an untrusted source, an attacker could exfiltrate any secret (CWE‑250). Because secrets often include deployment tokens, API keys, and credentials, the impact can be full repository compromise. The risk is classified as high due to the broad exposure and difficulty in revoking after leakage.

Replace secrets: inherit with explicit mapping of only the DockerHub credentials needed for the reusable workflow to prevent over‑privileging.

For reference: rule yaml.github-actions.security.secrets-inherit.secrets-inherit, CWE-250 (Execution with Unnecessary Privileges). Rated high.

I do not know the codebase, so please check the change fits how the rest of it works. Happy to adjust it or close this if the reasoning is off.


Found with automated scanning (RedGem) and reviewed before opening. If it is not useful, closing it is completely fine.

…he calling workflow's secrets to a reusable workflo
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant