Skip to content

[Aikido] AI Fix for Template Injection in GitHub Workflows Action - #15

Open
aikido-autofix[bot] wants to merge 1 commit into
main-workablefrom
fix/aikido-security-sast-128083687-rq9u
Open

aikido-autofix[bot] wants to merge 1 commit into
main-workablefrom
fix/aikido-security-sast-128083687-rq9u

Conversation

@aikido-autofix

Copy link
Copy Markdown

This patch mitigates template injection vulnerabilities in GitHub Workflows by replacing direct references with an environment variable.

✅ 2 issues fixed by this PR, including 2 critical 🚨 issues
Issue Severity           Description
Sast#340719234
🚨 CRITICAL
A GitHub Actions workflow step contains a template expression referencing potentially untrusted GitHub context fields. This may allow malicious input to be injected into shell commands, leading to a potential supply chain attack as tokens of the CI/CD pipeline could be exfiltrated.
Sast#340719293
🚨 CRITICAL
A GitHub Actions workflow step contains a template expression referencing potentially untrusted GitHub context fields. This may allow malicious input to be injected into shell commands, leading to a potential supply chain attack as tokens of the CI/CD pipeline could be exfiltrated.

High confidence: Aikido has a robust set of benchmarks for similar fixes, and they are proven to be effective.

@aikido-autofix
aikido-autofix Bot requested a review from a team as a code owner September 29, 2026 08:11
@aikido-autofix aikido-autofix Bot added the security Label created by Aikido AutoFix label Sep 29, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security Label created by Aikido AutoFix

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants