+
Skip to content

New audit: bot conditions #170

@woodruffw

Description

@woodruffw

TL;DR: if: github.actor == 'dependabot[bot]' can be exploited if it's composed with a dangerous trigger (like pull_request_target), since an attacker can open up a PR that's been manipulated such that the last actor/activity on the PR is Dependabot.

dependabot, dependabot[bot], and renovate[bot] are probably the main ones.

Ref: https://www.synacktiv.com/publications/github-actions-exploitation-dependabot

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions

    点击 这是indexloc提供的php浏览器服务,不要输入任何密码和下载