Skip to content

[static-analysis] RGS-012: Secret Exfiltration via Outbound HTTP Request in daily-byok-ollama-test.lock.ymlΒ #51944

Description

@github-actions

🚨 Runner-Guard Security Finding

Rule: RGS-012 β€” Secret Exfiltration via Outbound HTTP Request
Severity: High
File: .github/workflows/daily-byok-ollama-test.lock.yml
Line: 488 (also recurs at lines 496, 501 β€” 3 occurrences in this file)

Description

A run: block contains an outbound HTTP request command (curl, wget, httpie, python requests, node fetch, etc.) targeting a non-GitHub domain (i.e., not github.com, api.github.com, or ghcr.io) in a job context that has access to secrets or publishing capabilities. This pattern is a strong indicator of credential exfiltration β€” the primary objective of most GitHub Actions supply-chain attacks.

Impact

Attackers who achieve code execution in a CI runner (via expression injection, fork checkout, compromised action, etc.) need a way to exfiltrate stolen secrets to infrastructure they control. The most common method is an HTTP POST request to an attacker-owned domain carrying environment variables, secret values, or tokens as the request body. The combination of external HTTP requests with secrets access in a workflow is a high-confidence indicator worth manual review.

Investigation note: the flagged steps download and run the official Ollama install script from a GitHub Releases URL (https://github.com/ollama/ollama/releases/download/..., verified via sha256sum -c) and poll `(localhost/redacted) (the local Ollama service). Neither pattern matches secret exfiltration β€” this looks like a likely false positive from the rule's non-GitHub-domain heuristic combined with the job's secrets access. Still worth confirming no secret material can reach these commands.

Remediation

  • Confirm the job/step does not have unnecessary secrets exposure (scope secrets:/env: to only what's required).
  • If confirmed benign (install-script + checksum verification, localhost-only traffic), add a scoped runner-guard suppression with a justification comment.
  • Continue verifying third-party install scripts via checksum (already done here) as a baseline mitigation against supply-chain tampering.

Detected by runner-guard v2.6.0 β€” CI/CD source-to-sink vulnerability scanner
Workflow run: https://github.com/github/gh-aw/actions/runs/31460155227

Generated by πŸ“Š Static Analysis Report Β· agent Β· 150.9 AIC Β· βŒ– 33.6 AIC Β· ⊞ 11K Β· β—·

  • expires on Aug 17, 2026, 9:25 PM UTC-08:00

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions