Skip to content

scan-and-report.yml installs panic-attack from moving main — pin the scanner source (CWE-829) #212

Description

@hyperpolymath

.github/workflows/scan-and-report.yml installs the scanner with

cargo install --git https://github.com/hyperpolymath/panic-attack --branch main

A caller that pins the reusable workflow by SHA, for example echidna at @5ee2565…, still runs whatever binary main holds at run time. A push to main can therefore change every caller's scan results without changing any caller's pin (CWE-829). CodeRabbit raised this on hyperpolymath/echidna#399 (r4154702680). It is pre-existing: the earlier pin 27b3d93 has the same line.

Acceptance criteria

  • The install step names an immutable revision (--rev <40-hex sha>), not --branch main.
  • That revision is tied to the reusable's own revision, so bumping a caller's pin also moves the scanner. Either the workflow fixes --rev to the commit that contains it, or it takes an input defaulting to a SHA kept in step by the release process. The chosen mechanism is documented in the workflow header.
  • A check, or a bash -n plus grep test, fails if --branch or a tag reappears in the install line.
  • Callers (echidna, and any others found by gh search code "scan-and-report.yml@" and then verified by enumeration) are bumped to the fixed SHA.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething is broken or behaves incorrectly

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions