Testing flow includes a DeepSource secret

Disclosed: 2023-04-11 10:40:02 By triplesided To weblate
Low
Vulnerability Details
The testing workflow (https://github.com/WeblateOrg/wlc/blob/main/.github/workflows/test.yml) has a DeepSource secret included which would allow a malicious actor to use the DeepSource cli and access parts of the repo (https://deepsource.io/docs/cli/usage). Recommended usage would be to create a GitHub action environment secret and call this at runtime. https://deepsource.io/docs/analyzer/test-coverage#with-github-actions ## Impact Access to the DeepSource environment is gained through the token with the malicious actor able to report artifacts to DeepSource.
Actions
View on HackerOne
Report Stats
  • Report ID: 1927499
  • State: Closed
  • Substate: resolved
  • Upvotes: 7
Share this report