Skip to content

chore: Bump crowdin/github-action from 2.17.1 to 3.0.1 - #6389

Closed
dependabot[bot] wants to merge 1 commit into
stagingfrom
dependabot/github_actions/crowdin/github-action-3.0.1
Closed

dependabot[bot] wants to merge 1 commit into
stagingfrom
dependabot/github_actions/crowdin/github-action-3.0.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 3, 2026

Copy link
Copy Markdown
Contributor

Bumps crowdin/github-action from 2.17.1 to 3.0.1.

Release notes

Sourced from crowdin/github-action's releases.

v3.0.1

What's Changed

Full Changelog: crowdin/github-action@v3.0.0...v3.0.1

v3.0.0

Crowdin GitHub Action v3 runs on Crowdin CLI 5 🚀 - a complete rewrite that starts instantly and no longer requires Java. Your workflows, crowdin.yml configuration, and exit codes stay the same, so most setups upgrade with a one-line change:

-uses: crowdin/github-action@v2
+uses: crowdin/github-action@v3

Breaking changes

Only relevant if you pass custom CLI arguments via the command, command_args, or other *_args inputs:

  • pre-translate is now auto-translate (no alias); --translate-untranslated-only was removed - use --scope.
  • --plain was removed - use --output plain.
  • Redundant negatable flags were removed (e.g. --auto-update; --no-auto-update stays) - defaults are unchanged, simply drop them.

v3.0.0-next.3

No release notes provided.

v3.0.0-next.2

No release notes provided.

v3.0.0-next.1

No release notes provided.

v3.0.0-next.0

What's Changed

📖 Read more about the new CLI and share feedback - crowdin/crowdin-cli#1043

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [crowdin/github-action](https://github.com/crowdin/github-action) from 2.17.1 to 3.0.1.
- [Release notes](https://github.com/crowdin/github-action/releases)
- [Commits](crowdin/github-action@v2.17.1...v3.0.1)

---
updated-dependencies:
- dependency-name: crowdin/github-action
  dependency-version: 3.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies github_actions Pull requests that update GitHub Actions code labels Sep 3, 2026

- name: Download translations
uses: crowdin/github-action@v2.17.1
uses: crowdin/github-action@v3.0.1

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Semgrep identified an issue in your code:

The workflow runs crowdin/github-action@v3.0.1, whose tag can be silently repointed to attacker-controlled code. A compromised action release could steal WEBTEAM_CROWDIN_TOKEN or misuse GITHUB_TOKEN during scheduled or staging-triggered runs.

More details about this

crowdin/github-action@v3.0.1 uses a mutable version tag rather than an immutable commit. The owner of crowdin/github-action could repoint v3.0.1 to a malicious commit without changing this workflow, causing the Download translations step to execute attacker-controlled code.

A plausible attack:

  1. The attacker compromises or gains publishing access to the crowdin/github-action repository and moves the v3.0.1 tag to a malicious release.
  2. The scheduled Download translations job runs at 0 8 * * *, or a push to staging triggers it, and GitHub resolves crowdin/github-action@v3.0.1 to that new commit.
  3. The malicious action reads the step environment, including GITHUB_TOKEN, CROWDIN_PROJECT_ID, and secrets.WEBTEAM_CROWDIN_TOKEN, then uses the available token permissions to alter repository contents or create unauthorized pull requests. It could also replace the downloaded translation files with attacker-controlled content before create_pull_request: true submits the changes.

Because the workflow text remains unchanged, reviewing this file would not reveal that a later run executes different action code.

To resolve this comment:

✨ Commit fix suggestion

Suggested change
uses: crowdin/github-action@v3.0.1
# Replace with the verified 40-character commit SHA for the trusted v3.0.1 release.
uses: crowdin/github-action@<VERIFIED_VALUE_REQUIRED>
View step-by-step instructions
  1. Replace the mutable crowdin/github-action@v3.0.1 reference with the full 40-character commit SHA that corresponds to the trusted v3.0.1 release: uses: crowdin/github-action@<40-character-commit-sha>.
  2. Keep the existing env and with configuration unchanged. Verify that the replacement contains exactly 40 hexadecimal characters and points to the intended v3.0.1 commit, rather than a branch or version tag.
💬 Ignore this finding

Reply with Semgrep commands to ignore this finding.

  • /fp <comment> for false positive
  • /ar <comment> for acceptable risk
  • /other <comment> for all other reasons

Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by github-actions-mutable-action-tag.

You can view more details about this finding in the Semgrep AppSec Platform.

@dependabot @github

dependabot Bot commented on behalf of github Sep 7, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #6402.

@dependabot dependabot Bot closed this Sep 7, 2026
@dependabot
dependabot Bot deleted the dependabot/github_actions/crowdin/github-action-3.0.1 branch September 7, 2026 02:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants