Skip to content

[static-analysis] Report - 2026-08-15 #52839

Description

@github-actions

🔍 Static Analysis Report - 2026-08-15

Analysis Summary

  • Tools Used: zizmor, poutine, actionlint, runner-guard, syft, grype, yamllint, shellcheck
  • Total Findings: 1,805 (excluding SBOM inventory)
  • Workflows Scanned: 285 (285 succeeded, 0 failed)
  • Workflows Affected (by the 7 finding-producing tools): 21 of 285
  • Compiler-level warnings (separate from the 8 tools): 188 total (41 distinct message instances across ~30 workflows — template-separator style, missing-permission, /tmp/ reference, etc.)

Findings by Tool

Tool Total Critical High Medium Low
zizmor (security) 9 0 0 0 8 note + 1 warning
poutine (supply chain) 0 0 0 0 0
actionlint (linting) 0 - - - -
runner-guard (taint analysis) 122 0 111 11 0
syft (SBOM inventory) 10 images / 4,298 packages - - - -
grype (container CVEs) 1,674 67 433 774 167 low + 142 negligible + 91 unknown
yamllint (yaml linting) 0 - - - -
shellcheck (shell linting) 0 - - - -

Clustered Findings by Tool and Type

Zizmor Security Findings

Issue Type Severity Count Affected Workflows
github_action_from_unverified_creator_used Note 8 smoke-codex.lock.yml, copilot-setup-steps.yml, daily-elixir-credo-snippet-audit.lock.yml, link-check.yml (×2), dataflow-pr-discussion-dataset.lock.yml, hippo-embed.lock.yml, super-linter.lock.yml
pr_runs_on_self_hosted Warning 1 smoke-copilot-arm.lock.yml

All 8 unverified_creator_used sites already carry a # zizmor: ignore[...] suppression comment in source — they still surface in the compiled .lock.yml because zizmor scans the compiled output where the comment sits one line above the uses: step; these are accepted/reviewed, not new risk.

Poutine Supply Chain Findings

No findings — 0 issues detected by poutine across all 285 workflows.

Actionlint Linting Issues

No findings — actionlint reports "✓ Checked 285 workflow(s), ✓ No issues found."

Syft SBOM Inventory

Image Packages Notes
ghcr.io/github/serena-mcp-server:sha-891c160 2,314 Largest image by far; Debian-trixie based; unchanged digest for 5+ days
ghcr.io/github/gh-aw-firewall/agent:0.28.1 532 Version bumped from 0.27.44 this run
ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.1 348 Version bumped from 0.27.44 this run
ghcr.io/github/gh-aw-mcpg:v0.4.9 288
ghcr.io/github/gh-aw-firewall/api-proxy:0.28.1 193 Version bumped from 0.27.44 this run
ghcr.io/github/gh-aw-node 177
grafana/mcp-grafana:1.0.0-alpine 178
node:lts-alpine 165
ghcr.io/github/gh-aw-firewall/squid:0.28.1 63 Version bumped from 0.27.44 this run
ghcr.io/github/github-mcp-server:v1.9.0 40

These are shared engine/firewall infrastructure images used across the agentic-workflow fleet rather than images tied to one specific .md workflow source.

Runner-Guard Taint Analysis Findings

122 findings, unchanged in rule/count/workflow breakdown for the 4th consecutive scan (2026-08-12 → 2026-08-15).

Rule ID Name Severity Count Affected Workflows
RGS-004 Comment-Triggered Workflow Without Author Authorization Check High 98 dev-hawk.lock.yml
RGS-012 Secret Exfiltration via Outbound HTTP Request High 9 daily-model-inventory.lock.yml, daily-byok-ollama-test.lock.yml, docs-noob-tester.lock.yml, visual-regression-checker.lock.yml
RGS-018 Suspicious Payload Execution Pattern High 4 daily-byok-ollama-test.lock.yml, daily-cli-performance.lock.yml, daily-sentrux-report.lock.yml, smoke-claude.lock.yml
RGS-005 Excessive Permissions on Untrusted Trigger Medium 9 ai-moderator.lock.yml, q.lock.yml, agentic_commands.yml
RGS-019 Step Output Interpolated in run Block Medium 2 windows-cli-integration.yml, error-message-lint.yml

Issues created: none. Every Critical/High rule+file combination eligible for filing (RGS-004/dev-hawk, RGS-012 ×4, RGS-018 ×4 — 9 combos total) already has a closed issue on file (#50189, #51943, #51944, #50190, #51945, #35653, #47478, #46532, #47477), verified today via gh api search/issues?q=...state:open returning zero open matches. Per the dedup policy, closed dups are skipped rather than recreated.

Likely false positive confirmed: I directly inspected dev-hawk.lock.yml:127-131 (source of the 98 RGS-004 hits). The activation job's if: condition already checks github.event.workflow_run.actor.login against an explicit 9-name maintainer allowlist, plus fork/repository-id checks — a genuine author-authorization gate, just not expressed as an author_association check, which is the specific shape RGS-004's detector looks for. This is almost certainly why 12+ prior issues for this rule+file closed without a code change landing.

Grype Container Vulnerability Findings

Package family Severity Approx. count (Critical+High) Dominant image
Go stdlib / golang-1.24-go / golang-1.24-src High 107 serena-mcp-server, github-mcp-server, gh-aw-mcpg
openssl / libssl3t64 / libssl-dev / openssl-provider-legacy Critical/High 60 serena-mcp-server
libcurl3t64-gnutls Critical 14 serena-mcp-server
perl / libperl5.40 / perl-base / perl-modules-5.40 Critical 48 serena-mcp-server
nodejs / libnode115 / libnode-dev Critical 36 serena-mcp-server

32 distinct CVE/GHSA/GO identifiers account for the 67 critical findings; 65 of the 67 criticals (and 1,154 of all 1,674 grype findings) are in a single image: ghcr.io/github/serena-mcp-server:sha-891c160, a heavy (2,314-package) Debian-trixie based image whose digest hasn't changed across any of the last 5 scans.

All grype findings by image and severity
Image Critical High Medium Low Negligible Unknown
ghcr.io/github/serena-mcp-server:sha-891c160 65 395 423 96 115 60
ghcr.io/github/gh-aw-firewall/agent:0.28.1 0 5 291 62 19 6
ghcr.io/github/gh-aw-mcpg:v0.4.9 0 11 8 6 0 14
ghcr.io/github/github-mcp-server:v1.9.0 1 4 3 1 8 5
ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.1 0 5 10 0 0 6
ghcr.io/github/gh-aw-firewall/api-proxy:0.28.1 0 3 11 0 0 0
node:lts-alpine 1 6 12 2 0 0
ghcr.io/github/gh-aw-node 0 1 9 0 0 0
grafana/mcp-grafana:1.0.0-alpine 0 3 3 0 0 0
ghcr.io/github/gh-aw-firewall/squid:0.28.1 0 0 4 0 0 0

Yamllint YAML Linting Findings

No findings — 0 issues across 285 files.

Shellcheck Shell Linting Findings

No findings — 0 issues across all run steps in 285 files.

Top Priority Issues

1. serena-mcp-server critical/high CVE volume

  • Tool: grype
  • Count: 460 (65 critical + 395 high)
  • Severity: Critical/High
  • Affected: ghcr.io/github/serena-mcp-server:sha-891c160 (shared Serena MCP server image)
  • Description: A 2,314-package Debian-trixie image carrying long-unpatched OpenSSL, libcurl, Perl, Node.js, and Go stdlib CVEs. Digest unchanged across 5+ consecutive scans.
  • Impact: Largest single source of container vulnerability exposure in the fleet (69% of all grype findings). Any workflow that runs this MCP server inherits the full CVE surface.
  • Reference: https://github.com/github/gh-aw

2. RGS-004: Comment-Triggered Workflow Without Author Authorization Check

  • Tool: runner-guard
  • Count: 98 (single file)
  • Severity: High
  • Affected: dev-hawk.lock.yml
  • Description: Rule flags workflow_run-triggered jobs with secrets/write access lacking an author_association check.
  • Impact: Likely a scanner false positive here — the job already gates on an explicit actor-login allowlist (see investigation above). Real-world risk is low, but the recurring high-severity flag creates noise and could mask a genuine future issue if maintainers stop reviewing it.
  • Reference: https://github.com/Vigilant-LLC/runner-guard

3. RGS-012: Secret Exfiltration via Outbound HTTP Request

  • Tool: runner-guard
  • Count: 9
  • Severity: High
  • Affected: daily-model-inventory.lock.yml, daily-byok-ollama-test.lock.yml, docs-noob-tester.lock.yml, visual-regression-checker.lock.yml
  • Description: run: steps issue outbound HTTP requests (curl/wget) to non-GitHub domains from jobs with secrets access.
  • Impact: Several instances are documented as intentional (public model index downloads, localhost readiness probes with runner-guard:ignore comments) but not all sites carry a suppression comment/justification yet.
  • Reference: https://github.com/Vigilant-LLC/runner-guard

Fix Suggestion for RGS-012 (Secret Exfiltration via Outbound HTTP Request)

Issue: Outbound HTTP request in a run: block from a job with secrets access, without an explicit suppression/justification
Severity: High
Affected Workflows: 4 workflows, 9 sites

Prompt to Copilot Agent:

You are fixing a security finding identified by runner-guard (rule RGS-012: Secret
Exfiltration via Outbound HTTP Request).

Vulnerability: A `run:` block issues an outbound HTTP request (curl, wget, node fetch, etc.)
to a domain other than github.com / api.github.com / ghcr.io, inside a job that has access to
secrets or publishing capabilities. This pattern is the primary mechanism attackers use to
exfiltrate stolen credentials once they achieve code execution in a CI runner (e.g. via
expression injection or a compromised action).

Why it matters: even a legitimate outbound call (downloading a public index, polling a local
dev server) is indistinguishable to the scanner from credential exfiltration unless it's
either restricted to a safe/allowlisted domain, stripped of secrets, or explicitly reviewed
and annotated as safe.

Required fix, for each flagged `run:` step:
1. Confirm the destination domain and payload: does the request send any `secrets.*` or
   `env.*` value in the URL, headers, or body? If yes, remove the secret from the request —
   this is a real vulnerability, not a false positive.
2. If the request is safe (public read-only GET, loopback/localhost probe, no secrets in the
   request), add a `# runner-guard:ignore RGS-012 -- <reason>` comment directly above the
   `run:` step explaining why it's safe, mirroring the existing pattern already used in
   daily-rendering-scripts-verifier.md and daily-model-inventory.md for their loopback checks.
3. If the job doesn't need secrets for this step, consider moving the HTTP call to a job (or
   step) with reduced `permissions:` / no secret exposure, so the taint path the rule is
   detecting no longer exists.
4. Recompile and confirm runner-guard no longer flags RGS-012 for the updated site (or that
   the ignore comment suppresses it with a clear justification on record).

Example:
Before (no justification, scanner cannot distinguish from exfiltration):
```yaml
- name: Fetch model index
  run: curl -fsS (models.dev/redacted) -o "$OUT/api.json"

After (annotated as a reviewed, safe, non-secret-bearing request):

- name: Fetch model index
  # runner-guard:ignore RGS-012 -- unauthenticated GET from a public read-only model index; no secrets are sent.
  run: curl -fsS (models.dev/redacted) -o "$OUT/api.json"

Please apply this review to the 9 flagged sites across: .github/workflows/daily-model-inventory.md,
.github/workflows/daily-byok-ollama-test.md, .github/workflows/docs-noob-tester.md,
.github/workflows/visual-regression-checker.md (source files for the flagged .lock.yml outputs).


**Reference**: https://github.com/Vigilant-LLC/runner-guard (rule does not publish a standalone docs page beyond the finding description)

### All Findings Details

<details>
<summary><b>Detailed Findings by Workflow</b></summary>

#### dev-hawk.lock.yml
- **RGS-004** (High) × 98 — Comment-Triggered Workflow Without Author Authorization Check. Closed dup of #50189. Likely false positive — actor allowlist gate confirmed present at lines 127-131.

#### daily-model-inventory.lock.yml
- **RGS-012** (High) × 4 — Secret Exfiltration via Outbound HTTP Request. Closed dup of #51943.

#### daily-byok-ollama-test.lock.yml
- **RGS-012** (High) × 2 — Closed dup of #51944.
- **RGS-018** (High) × 1 — Suspicious Payload Execution Pattern. Closed dup of #35653.

#### docs-noob-tester.lock.yml
- **RGS-012** (High) × 1 — Closed dup of #50190.

#### visual-regression-checker.lock.yml
- **RGS-012** (High) × 2 — Closed dup of #51945.

#### daily-cli-performance.lock.yml
- **RGS-018** (High) × 1 — Closed dup of #47478.

#### daily-sentrux-report.lock.yml
- **RGS-018** (High) × 1 — Closed dup of #46532.

#### smoke-claude.lock.yml
- **RGS-018** (High) × 1 — Closed dup of #47477.

#### ai-moderator.lock.yml
- **RGS-005** (Medium) × 5 — Excessive Permissions on Untrusted Trigger.

#### q.lock.yml
- **RGS-005** (Medium) × 3.

#### agentic_commands.yml
- **RGS-005** (Medium) × 1.

#### windows-cli-integration.yml
- **RGS-019** (Medium) × 1 — Step Output Interpolated in run Block.

#### error-message-lint.yml
- **RGS-019** (Medium) × 1.

#### Zizmor note/warning sites
- smoke-codex.lock.yml:2351, copilot-setup-steps.yml:42, daily-elixir-credo-snippet-audit.lock.yml:448, link-check.yml:37 & :46, dataflow-pr-discussion-dataset.lock.yml:503, hippo-embed.lock.yml:432, super-linter.lock.yml:1757 — `github_action_from_unverified_creator_used` (Note, all suppressed in source).
- smoke-copilot-arm.lock.yml:460 — `pr_runs_on_self_hosted` (Warning).

</details>

### Historical Trends

- **Previous Scan**: 2026-08-14 (run [§31772315141](https://github.com/github/gh-aw/actions/runs/31772315141))
- **Total Findings Then**: 1,780
- **Total Findings Now**: 1,805
- **Change**: +25 (+1.4%), driven entirely by grype (1,649 → 1,674); zizmor, poutine, actionlint, runner-guard, yamllint, and shellcheck are all unchanged.

#### New Issues
None. No new rule IDs, workflows, or issue types appeared today.

#### Resolved Issues
None outstanding — RGS-004/012/018 continue to recur daily as closed-issue dups (no code changes have landed for any of the 9 tracked rule+file combos across at least 5 days).

#### Notable trend
`gh-aw-firewall` images (agent/api-proxy/cli-proxy/squid) were bumped from `0.27.44` to `0.28.1` in this run, reshuffling per-image grype counts (squid 22→4, api-proxy 25→14, cli-proxy 24→21, agent 377→383) without a material change in total OS CVE exposure. `serena-mcp-server:sha-891c160` has not changed digest in 5+ days and remains responsible for 69% of all grype findings and 97% of criticals — it is the single highest-leverage target for reducing container vulnerability count fleet-wide.

### Recommendations

1. **Immediate**: None of today's Critical/High runner-guard findings require new action — all 9 rule+file combos are already tracked in closed issues. Recommend a maintainer review whether #50189 (RGS-004/dev-hawk) should be reopened with a note that it's likely a detector false positive, or whether the rule itself should be tuned to also accept actor-login-allowlist checks as a valid authorization gate.
2. **Short-term**: Review and annotate (or fix) the 9 RGS-012 outbound-HTTP sites per the fix prompt above — several already have `runner-guard:ignore` justification comments nearby, but not all 9 flagged lines do.
3. **Long-term**: Rebuild/replace `ghcr.io/github/serena-mcp-server:sha-891c160` — a newer upstream base image would likely resolve the bulk of the 67 criticals and 433 highs in one move, given the image hasn't been refreshed in 5+ tracked days.
4. **Prevention**: Continue tracking image digest changes in cache memory to distinguish "new CVE disclosed against pinned digest" from "image actually updated" — today's gh-aw-firewall version bump was a useful example of the latter.

### Next Steps

- [ ] Maintainer decision on RGS-004/dev-hawk: reopen #50189 with a false-positive note, or tune the runner-guard rule to recognize actor-allowlist gates
- [ ] Annotate remaining un-suppressed RGS-012 sites with `runner-guard:ignore` + justification, or fix genuine secret-bearing requests
- [ ] Evaluate refreshing `serena-mcp-server` base image to cut critical/high CVE count
- [ ] No actionlint/yamllint/shellcheck/poutine work needed this cycle — all clean
- [ ] Continue daily trend tracking in cache memory

**References:**
- [§31865340223](https://github.com/github/gh-aw/actions/runs/31865340223) (this scan)
- [§31772315141](https://github.com/github/gh-aw/actions/runs/31772315141) (2026-08-14 scan)

> Generated by [📊 Static Analysis Report](https://github.com/github/gh-aw/actions/runs/31865340223) · agent · 183 AIC · ⌖ 6.26 AIC · ⊞ 11K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fstatic-analysis-report%22&type=issues)
> - [x] expires <!-- gh-aw-expires: 2026-08-22T05:17:59.634Z --> on Aug 21, 2026, 9:17 PM UTC-08:00

<!-- gh-aw-agentic-workflow: Static Analysis Report, engine: claude, model: agent, id: 31865340223, workflow_id: static-analysis-report, run: https://github.com/github/gh-aw/actions/runs/31865340223 -->

<!-- gh-aw-workflow-id: static-analysis-report -->
<!-- gh-aw-workflow-call-id: github/gh-aw/static-analysis-report -->

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions