Repository navigation
chore: Bump crowdin/github-action from 2.17.1 to 3.0.1 - #6389
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [crowdin/github-action](https://github.com/crowdin/github-action) from 2.17.1 to 3.0.1. - [Release notes](https://github.com/crowdin/github-action/releases) - [Commits](crowdin/github-action@v2.17.1...v3.0.1) --- updated-dependencies: - dependency-name: crowdin/github-action dependency-version: 3.0.1 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
|
|
||
| - name: Download translations | ||
| uses: crowdin/github-action@v2.17.1 | ||
| uses: crowdin/github-action@v3.0.1 |
There was a problem hiding this comment.
Semgrep identified an issue in your code:
The workflow runs crowdin/github-action@v3.0.1, whose tag can be silently repointed to attacker-controlled code. A compromised action release could steal WEBTEAM_CROWDIN_TOKEN or misuse GITHUB_TOKEN during scheduled or staging-triggered runs.
More details about this
crowdin/github-action@v3.0.1 uses a mutable version tag rather than an immutable commit. The owner of crowdin/github-action could repoint v3.0.1 to a malicious commit without changing this workflow, causing the Download translations step to execute attacker-controlled code.
A plausible attack:
- The attacker compromises or gains publishing access to the
crowdin/github-actionrepository and moves thev3.0.1tag to a malicious release. - The scheduled
Download translationsjob runs at0 8 * * *, or a push tostagingtriggers it, and GitHub resolvescrowdin/github-action@v3.0.1to that new commit. - The malicious action reads the step environment, including
GITHUB_TOKEN,CROWDIN_PROJECT_ID, andsecrets.WEBTEAM_CROWDIN_TOKEN, then uses the available token permissions to alter repository contents or create unauthorized pull requests. It could also replace the downloaded translation files with attacker-controlled content beforecreate_pull_request: truesubmits the changes.
Because the workflow text remains unchanged, reviewing this file would not reveal that a later run executes different action code.
To resolve this comment:
✨ Commit fix suggestion
| uses: crowdin/github-action@v3.0.1 | |
| # Replace with the verified 40-character commit SHA for the trusted v3.0.1 release. | |
| uses: crowdin/github-action@<VERIFIED_VALUE_REQUIRED> |
View step-by-step instructions
- Replace the mutable
crowdin/github-action@v3.0.1reference with the full 40-character commit SHA that corresponds to the trustedv3.0.1release:uses: crowdin/github-action@<40-character-commit-sha>. - Keep the existing
envandwithconfiguration unchanged. Verify that the replacement contains exactly 40 hexadecimal characters and points to the intendedv3.0.1commit, rather than a branch or version tag.
💬 Ignore this finding
Reply with Semgrep commands to ignore this finding.
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by github-actions-mutable-action-tag.
You can view more details about this finding in the Semgrep AppSec Platform.
|
Superseded by #6402. |
Bumps crowdin/github-action from 2.17.1 to 3.0.1.
Release notes
Sourced from crowdin/github-action's releases.
Commits
71fdb88chore: CLI 5.0.106edd94docs: update the v3 announcement64eab86ci: support v3 in update-main-version workflowe4a6c13feat: v3 release (#315)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)