3 ms·
Running CI against arbitrary code is extremely difficult to do securely and I'm not sure anyone does more than a token effort. Test infrastructure is not design
by kanox 6y ago
Running CI against arbitrary code is extremely difficult to do securely and I'm not sure anyone does more than a token effort. Test infrastructure is not designed to run against malicious code.
One of the examples dumps environment variables which may contain secrets by injecting code through a github action. What's stopping code inside a PR from sending the same info over email?
- takluyver 6y agoI believe CI on pull requests runs without the secrets, to avoid precisely that issue.
- amscanne 6y agoYes, the problem is that GitHub did not seem to consider that “malicious input” can include any content that is provided and parsed in some way. Unfortunately, all of stdout is parsed, and often includes things like issue titles, descriptions, commit messages, etc.