Repository navigation
fix(security): redact URL credentials, prevent report injection, harden HTTP handling - #4
Open
devin-ai-integration[bot] wants to merge 1 commit into
Open
devin-ai-integration[bot] wants to merge 1 commit into
devin-ai-integration[bot] wants to merge 1 commit into
Conversation
… bump @actions/github - redact user:password userinfo from console, JSON, and Markdown reports - render untrusted URLs, file paths, and error text as unescapable inline code so scanned docs cannot inject Markdown/HTML into PR comments - reject redirects to non-http(s) protocols and cap response bodies at 5MB - mask the action github-token via core.setSecret - upgrade @actions/github to ^9.1.1 to drop vulnerable undici 5.x
Author
🤖 Devin AI EngineerI'll be helping with this pull request! Here's what you should know: ✅ I will automatically:
Note: I can only respond to comments from users who have write access to this repository. ⚙️ Control Options:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Security review of the whole codebase plus fixes for the issues that are actually exploitable. This is a CLI/GitHub Action with no server, database, or templating, so the SQLi / CORS / debug-endpoint / auth classes don't apply; the real attack surface is untrusted content coming out of scanned Markdown (which, in the Action, is attacker-controlled on a fork PR) and untrusted HTTP responses.
Fixed:
Credential leak into logs, JSON reports, and PR comments. A link like
https://user:token@internal.example.com/was echoed verbatim into the console report,report.json, the Step Summary, and the PR comment. NewredactUrlCredentials()inutils.tsrewrites userinfo to***and is applied on every output path (truncateUrl,toJsonReportforurl/finalUrl/redirectChain,toMarkdownReport).Markdown/HTML injection into the bot's PR comment. The URL was interpolated into a fixed single-backtick span, and error text / file paths were interpolated raw:
A URL containing a backtick (e.g.
https://example.com/`</details><img src=x>) closed the span and let a PR author write arbitrary Markdown/HTML — including tracking images and content that hides the rest of the report — into a comment posted by the repo's own token.inlineCode()grows the fence past the longest backtick run in the value and collapses newlines, so it cannot be escaped.Redirects were followed to arbitrary protocols.
performRequestresolvedLocationwithnew URL(loc, current)and re-requested it without re-validating the scheme, so a server could bounce the checker tofile:///other schemes. Now revalidated withisValidUrland rejected.Unbounded response bodies. The HEAD→GET fallback buffered the entire body in memory (a malicious or misbehaving host could OOM the runner).
maxContentLength/maxBodyLengthare now capped at 5 MB.github-tokenwas never masked — addedcore.setSecret(token)so a non-default token passed via the input can't be printed by later log output.Vulnerable runtime dependency:
@actions/github@7pinnedundici@5.29.0(high-severity: request smuggling, unbounded decompression, several CRLF-injection advisories). Bumped to^9.1.1, which resolvesundici@6.28.0;npm audit fixalso cleaned up the remaining non-breaking transitive advisories. No runtime vulnerabilities remain.Checked and found clean: no hardcoded secrets/keys anywhere; no
eval/child_process/dynamic code loading; config input validated by the existing zod schema; the Markdown regexes and the ignore-pattern matcher were fuzzed with adversarial inputs (long unterminated links, quote/backtick runs, 60 KB tokens) with no ReDoS blowup.Not fixed, deliberately — the remaining
npm auditfindings are all dev-only (vitest/vite/esbuild/postcss), reachable only via the Vitest UI/dev server, which this repo never runs. The fix requiresvitest@4, a breaking major published 2026-08-18 (too new to vet); worth doing as a separate dependency PR.Also worth considering (out of scope here): the checker will happily fetch
http://localhost:*/ link-local addresses found in docs — harmless on GitHub-hosted runners, but an SSRF primitive for anyone running this Action on a self-hosted runner. A--block-private-hosts-style option (default on in the Action) would close it.Link to Devin session: https://app.devin.ai/sessions/8b2c45bbb02c4cd498f0882796aba23e
Requested by: @lahcenassmira