Skip to content

[plan] Fix github-env HIGH vulnerability in ci-doctor and dev-hawk workflows #22249

Description

@github-actions

Objective

Fix the github-env HIGH severity zizmor finding in ci-doctor.md and dev-hawk.md by replacing >> $GITHUB_ENV patterns with safer alternatives.

Context

Source: Static Analysis Report - 2026-03-22

Vulnerability: Dangerous use of the GITHUB_ENV environment file. Writing to $GITHUB_ENV from within a step can allow environment variable injection if any prior step is compromised.

Affected files:

  • .github/workflows/ci-doctor.md (compiled: ci-doctor.lock.yml)
  • .github/workflows/dev-hawk.md (compiled: dev-hawk.lock.yml)

Current patterns in compiled output (ci-doctor.lock.yml):

echo "GH_AW_SAFE_OUTPUTS=..." >> "$GITHUB_ENV"
echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=..." >> "$GITHUB_ENV"
echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=..." >> "$GITHUB_ENV"
echo "GH_AW_AGENT_OUTPUT=..." >> "$GITHUB_ENV"
echo "GH_HOST=..." >> "$GITHUB_ENV"

These patterns are systemic (generated by the framework), so the fix may need to happen in the workflow compiler or the shared setup action.

Approach

  1. Investigate source of >> $GITHUB_ENV: Determine whether these are generated by the compiler or come from actions/setup/sh/*.sh scripts
  2. Replace with $GITHUB_OUTPUT: Where variables are passed to subsequent steps in the same job, use step outputs ($GITHUB_OUTPUT) instead of environment file injection
  3. Use env: blocks on steps: Where env vars are needed within a single step, pass them via the step's env: block rather than writing to $GITHUB_ENV
  4. If the pattern is systemic in the compiler, update the relevant compiler template or setup script
  5. Run make recompile after any compiler/script changes

Files to Investigate

  • actions/setup/sh/*.sh — shell scripts that may write to $GITHUB_ENV
  • pkg/workflow/*.go — compiler templates that may generate $GITHUB_ENV writes
  • .github/workflows/ci-doctor.md and dev-hawk.md — check if there are workflow-level customizations

Acceptance Criteria

  • Zizmor no longer reports github-env HIGH for ci-doctor and dev-hawk
  • Variables previously set via $GITHUB_ENV are still accessible in subsequent steps (using $GITHUB_OUTPUT or step-scoped env:)
  • Recompiled workflows pass make recompile and CI

Generated by Plan Command for issue #discussion #22240 · ◷

  • expires on Mar 24, 2026, 8:48 AM UTC

Activity

  1. github-actions commented on Mar 23, 2026

    @github-actions
    ContributorAuthor

    🍪 Issue Monster has assigned this to Copilot!

    I've identified this issue as a good candidate for automated resolution and assigned it to the Copilot coding agent.

    The Copilot coding agent will analyze the issue and create a pull request with the fix.

    Om nom nom! 🍪

    🍪 Om nom nom by Issue Monster · ◷

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions