Skip to content

[Aikido] Pin safe-chain installer version and add SHA256 verification in GitHub Actions workflows - #745

Closed
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/code-audit-137919779-vaqq
Closed

aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/code-audit-137919779-vaqq

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Oct 8, 2026

Copy link
Copy Markdown

This patch mitigates GitHub Actions CI supply-chain vulnerabilities by replacing dynamic installer downloads with pinned version references and SHA256 checksum verification. Previously, all eight workflows downloaded the latest safe-chain installer without version or integrity checks, creating exposure to potential compromised releases. The fix introduces environment variables for explicit version pinning (1.0.0) and SHA256 hash validation before execution, ensuring only verified installer versions are executed. Changes were applied consistently across all affected workflow files: benchmark.yml, end2end.yml, lint.yml, publish.yml, qa-tests.yml, smoke-test-ffi.yml, test-publish.yml, and unit-test.yml.

✅ 1 issue fixed by this PR
Issue Severity           Description
CodeAudit#811707762
HIGH
This is one repository-wide CI supply-chain vulnerability with repeated sinks, not separate findings per workflow. The external release response is treated as executable code at runtime. If the upstream Safe-Chain release account, release automation, release asset, or delivery path is compromised, the next applicable workflow run executes attacker-controlled code on the runner. That code can read checked-out private source, modify build and test inputs, tamper with artifacts and results, and access credentials or tokens exposed to the individual job. Some release-related workflows grant OIDC token-request permission, but the repository evidence does not establish that any external cloud trust policy accepts such tokens or that every affected job has publication credentials; those outcomes are not assumed. The distinct fix is to pin and cryptographically verify the installer everywhere, or vendor it/use a reviewed action.

@hansott hansott closed this Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant