4 ms·
The point is that any of those tags can be replaced maliciously, after the fact.
by BHSPitMonkey 2y ago
The point is that any of those tags can be replaced maliciously, after the fact.
- mroche 2y agoIf tags are the way people want to work, then there needs to be a new repo class for actions which explicitly removes the ability to delete or force push tags across all branches. And enforced 2FA. Using a commit hash is the second most secure option. The first (in my eyes) is vendoring the actions you want to use in your user/org's namespace. Maintaining when/if to sync or backport upstream modifications can protect against these kinds of attacks. However, this does depend on the repo being vetted ahead of time, before being vendored.
- robertlagrant 2y agoSorry I followed up to this point - how can this be done?
- GauntletWizard 2y agoFrom the GitHub UI, very simply. Go to a repo you administer, in the /tags page, and each tag has a ... Drop-down menu with a delete option. Then upload a new tag by that name. Tags are not automatically updated from remotes on pull (they are automatically created locally if it's a new tag). This doesn't mean that the remote can't change what the tag points to, only that it's easy to spot. Edit: and to be clear, for many years after release, this was the recommendation from the Visual Source Safe team (Yes, that team developed GitHub Actions) for managing your actions. Tell people to use "v1", then delete the tag update it each time.
- robertlagrant 2y agoAh - is the problem a malicious administrator of the repo you're pulling from?
- GauntletWizard 2y agoYes, exactly that. Or anyone who hacks their Github account.