Skip to content

harden docker workflow against CI injection attacks - #245

Merged
umputun merged 3 commits into
umputun:masterfrom
paskal:fix/ci-security-hardening
Mar 5, 2026
Merged

umputun merged 3 commits into
umputun:masterfrom
paskal:fix/ci-security-hardening

Conversation

@paskal

@paskal paskal commented Mar 2, 2026

Copy link
Copy Markdown
Contributor

Summary

  • add top-level permissions: contents: read, packages: write (least privilege)
  • add github.event.workflow_run.event == 'push' guard to prevent Docker builds from firing on PR-triggered CI completions
  • replace direct ${{ github.event.workflow_run.head_branch }} interpolation in run: blocks with env: variable mapping to prevent shell injection via attacker-controlled branch names

Context: https://www.stepsecurity.io/blog/hackerbot-claw-github-actions-exploitation

- add permissions: contents: read, packages: write (least privilege)
- add event == 'push' guard to prevent workflow_run firing on PR events
- use env: mapping for head_branch instead of direct ${{ }} interpolation in shell
@paskal
paskal requested a review from umputun as a code owner March 2, 2026 21:07
steps.tags.outputs.* values derived from head_branch were still
interpolated via ${{ }} in run: blocks. Now passed via env:.

@umputun umputun left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm, thx

@umputun
umputun merged commit f3f7ade into umputun:master Mar 5, 2026
2 checks passed
@paskal
paskal deleted the fix/ci-security-hardening branch March 7, 2026 03:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants