14 comments

  • inahga 52 minutes ago
    I probably would have made the same mistake. It is negligent to write GitHub Actions without using static analysis.

    Use zizmor in CI https://github.com/zizmorcore/zizmor

        error[template-injection]: code injection via template expansion
          --> .github/workflows/jira_issue.yml:24:29
           |
        22 |         run: |
           |         --- this run block
        23 |           # Escape special characters in title and body
        24 |           TITLE=$(echo '${{ github.event.issue.title }}' | sed 's/"/\\"/g' | sed "s/'/\\\'/g")
           |                             ^^^^^^^^^^^^^^^^^^^^^^^^ may expand into attacker-controllable code
           |
           = note: audit confidence → High
           = note: this finding has an auto-fix
    • btown 37 minutes ago
      This is a really cool tool! Would zizmor have caught the below as well? From the article:

      > The workflow had an if: condition that appeared protective:

      > if: (github.event_name == 'issues' && github.event.pull_request.user.login != 'whitesource-for-github-com[bot]')

      > However, on issues events, github.event.pull_request is always null. So the condition reduces to (null != 'whitesource-for-github-com[bot]'). This is always true, and every GitHub user passes the gate.

      Speaking broadly: it's a massive reminder that AI is trained on a veritable mountain of insecure GitHub Actions examples, many of which "fail open" in highly unpredictable ways even if widely used. Actions is almost unique in this regard, with the combination of a difficult-to-audit language and the type of privileged RCE environment that makes attackers salivate.

      (I do think that this stems in part from GitHub's often-inscrutable documentation, and a decision to release Actions without a robust security linting solution, leaving that to the community - but I do understand how it's an uphill battle, and we could have ended up with a much less flexible CI/CD system without this having shipped fast.)

    • dataflow 3 minutes ago
      [delayed]
    • brewmarche 7 minutes ago
      I get scared when I see these string interpolations in GitHub Actions.

      Use `env:` instead and just work with environment variables in your shell script.

      Yes, you still need to vet your script. Quoting is a common source of problems. Use shellcheck. Do not call eval/source/python/perl/whatever with untrusted input.

      But you removed one layer of problems already by not pasting a value into your shell script code directly.

    • netdevphoenix 23 minutes ago
      Difference is you are not a trillion dollar plus technology hyped as a harbinger of civilisational change.
      • SV_BubbleTime 2 minutes ago
        I mean… it’s only Monday!

        But yes, there is an interesting change in the past decade, where everything new must be over-hyped.

        Perhaps it is attention overload and needing to shout. Perhaps it’s that technological progress has significantly slowed while communication options have exploded (coincidence?).

        I look at it a lot like EVs. They’re great, if your use case is inside the specific band. But, that isn’t who they were being marketed to. And now… “pushback” is putting it lightly.

    • madeofpalk 40 minutes ago
      Github Actions is actually so incredibly scary to have on public repo. It's full of so many footguns that's far from obvious.

      It's a shame Github is buried under their current server issues, because it would be great to get improvements all of this - at least warning/erroring on these sorts of things themselves.

  • mjr00 1 hour ago
    It's interesting to look at what was being attempted when the vulnerability was introduced[0]

    > Workflows like jira_close.yml use deprecated atlassian JIRA actions and have a dependency on the gh-actions repo. This is not ideal and unecessarily complex. PR updates jira_close workflow to use direct API calls via curl. It preserves custom fields used too.

    I won't speak to this projects' management and how they prioritize things, but from my own experience, pre-AI, this type of change would have been firmly in the "this is a minor annoyance, put it in the Tech Debt Backlog alongside the 50000 other tickets" and never actually done. The cost of a human investing the time understanding how to fix the problem, doing code changes, testing them, and deploying them is just way too high for what actual value this change brings, which is close to nothing.

    Now with AI, it's as simple as firing up an agent and telling them to make a change; as much effort as writing that backlog Jira ticket in the first place.

    Similar to the problem open source is having with low-value PRs, companies are going to have to start realizing that code is not free to review or maintain, even when it's generated for ~free, in their internal processes. Just because an agent can fix a minor tech debt annoyance with a few lines of instructions doesn't mean it should.

    [0] https://github.com/snowflakedb/snowflake-connector-net/pull/...

    • fg137 48 minutes ago
      I have seen plenty of "my backlog has never been shorter" comments here.

      I'm interested in how that turns out 6 months later.

      In my team, we have plenty of enhancement requests from users. We address those that make obvious sense and are trivial to do but withhold from others, even though the code change itself is likely small. Because we don't know if there is more than a single user that can actually benefit from it, if it has unintended consequences, or if it causes maintainence issue down the road.

      • ctoth 19 minutes ago
        > but withhold from others, even though the code change itself is likely small.

        Prediction: programming is going to change massively not only because the cost of creating code will go down, but because people are so tired of this sort of gatekeeping "we know better" from programmers.

        • mjr00 9 minutes ago
          > Prediction: programming is going to change massively not only because the cost of creating code will go down, but because people are so tired of this sort of gatekeeping "we know better" from programmers.

          I assume the "gatekeeping" decision to not implement a feature request is coming from someone responsible for the product, not from a developer.

  • procone 1 hour ago
    YAML is a nightmare fuel spec.

    In its quest to make markup "human readable", it has created countless footguns.

    I honestly prefer XML at this point.

    • doix 29 minutes ago
      Yeah, the YAMLification of everything kinda killed my ability to understand "everything". Previously, if you knew the Linux userland well, I felt like you could figure anything out with enough digging.

      Take CI for example, it was Jenkins and it ran a csh/bash/zsh whatever script and captured the output. Nice and simple (even if the scripts sometimes got insane).

      GitHub actions is nothing like that. Weird home grown extensions to YAML with their own idiosyncrasies and dynamically pulling in plugins from god knows where. You can't just take a workflow and execute it locally like you could with a bash script.

      • muvlon 14 minutes ago
        And worse: GitHub Actions not a full-fledged programming environment by itself either, so you're inevitably going to have to deal with nontrivial shell scripts on top of all the YAML mess.
        • fragmede 0 minutes ago
          Yeah. It makes sense when you're standing right next to it, but you take a step back and go "that doesn't look right". GitHub actions is the faster horse instead of a car.
    • anonymars 1 hour ago
      In a similar vein, JSON's lack of comments makes me marvel at how consistently JavaScript seems to choose the worse option. I'm oh so glad it found its way into config files
      • an0malous 40 minutes ago
        Seems more like the opposite vein, JSON's lack of comments or other affordances has kept it safe from footguns
        • madeofpalk 39 minutes ago
          Of all the problems with YAML, how is comments a footgun?
      • xgulfie 26 minutes ago
        I've seen people put "//" keys in their json lol
    • fmbb 1 hour ago
      It’s find for actions and workflows as long as you do no interpolation and logic.

      Better move as much of that as possible into your own scripts. And your scripts can be portable between forges, and even run locally!

      • RHSeeger 1 hour ago
        The YAML spec/parse _itself_ does interpolation and logic - incorrectly in some cases. YAML is pretty much never the right solution.
      • NewJazz 1 hour ago
        Assigning an env var to an empty variable (env: { myvar: ${{unsetfoo}} }) should trigger an error, not silently pass an empty string.
        • ezfe 1 hour ago
          What does that have to do with YAML?
      • formerly_proven 56 minutes ago
        > It’s find for actions and workflows as long as you do no interpolation and logic.

        How do you specify actions and workflows without interpolation and logic kind sir?

    • hbn 49 minutes ago
      I never figured out how the hell to write YAML and I definitely won't now that I trust the AI to do a better job than me. It's so unintuitive.

      Every time I've tried in the past, something as simple as making a value a list had some nonsense expectations. I can't wrap my head around how that spec got any traction and wasn't laughed off the face of the earth the first time it was looked at by someone who didn't create it.

    • cgannett 1 hour ago
      And thus procone spoketh the truth.
      • codeduck 1 hour ago
        In accordance with the prophecy.
  • sippeangelo 2 hours ago
    The title is actually "Wiz Red Agent Finds Its Way Into Snowflake’s Internal Jira Due to an AI-Generated GitHub Copilot Autofix"
    • galnagli 1 hour ago
      Too long for hackernews :(
  • vultour 1 hour ago
    The first linked PR (#1218) has only one commit co-authored by Copilot and it's not related to the vulnerability, and neither are the other suggestions in the PR. Am I missing something?
    • galnagli 1 hour ago
      Github is having some problems -- will check! thanks a lot!
  • teraflop 1 hour ago
    > The workflow had an if: condition that appeared protective:

    > if: (github.event_name == 'issues' && github.event.pull_request.user.login != 'whitesource-for-github-com[bot]')

    > However, on issues events, github.event.pull_request is always null.

    This is extra dumb because even if you thought this condition was correctly testing the user's identity, it shouldn't have "appeared protective" upon even a moment's thought. If it worked correctly, it would obviously just exclude one bot user while allowing all other users, so it wouldn't provide any protection at all.

    But more likely, this condition was never intended to be "protective" at all, and it's only being described that way because the writeup is LLM slop.

  • johnwils 27 minutes ago
    The env + jq was there on purpose. Autofix swapped it for a string in a shell. That's the part that needed a person on the diff.
  • chrisjj 1 hour ago
    > a single quote in the title breaks out of echo '...' and allows arbitrary command execution.

    Quote injection still alive and well in 2026. Gawd.

    • myself248 9 minutes ago
      It's appalling that computing in general, and unix in particular, seems to have this habit of intermingling payload and overhead.

      It's like in-band signalling in the telephone network, where if you whistled the right tones into your call, you could affect the way the network processed said call. Except Ma Bell responded to that system being exploited by designing a comprehensive overhaul of the way signalling was handled, and spent a squadzillion dollars upgrading millions of tons of switching equipment to categorically exclude that entire class of attack from ever being possible.

      Software, on the other hand, would need to replace no equipment whatsoever. Existing processors are perfectly capable of running code that handles the length of a string separately from its contents. There are existing languages that do this, they're just.... not used. String escapes and buffer overflows exist, going on decades now, due to nothing more than laziness, inertia, and negligence.

    • danqqqq 1 hour ago
      [dead]
  • TheRealPomax 1 hour ago
    No, Snowflake allowing autofixes compromised their Jira. If you tell someone to shoot you in the foot, and they shoot you in the foot, you shot yourself in the foot, just with more steps. If someone else finds the memo that says you've set up foot shooting as a service, and then they trigger that service, you still shot yourself in the foot.
    • rawgabbit 1 hour ago
      Help me understand. Snowflake configured their Github repo to allow auto fixes by Copilot. It got merged automatically without anyone's review? And introduced essentially script-injection vulnerability through the title field?

      If this is the case, I would say Snowflake should shut down its repo and get off Github asap.

      • rafram 46 minutes ago
        No. A Snowflake maintainer opened a PR, Copilot suggested a change (introducing a vulnerability), the maintainer accepted and committed it to their PR, and another Snowflake maintainer approved and merged the PR.
        • lelanthran 8 minutes ago
          And that's going to continue because no one is reading the code even when they approve it.

          It's a very strange thing indeed, but not unexpected: we warned that skills not used will eventually atrophy.

  • forestry 2 hours ago
    Peer review of changes is still important.
    • Rumudiez 1 hour ago
      Multi-model cross-review is important
      • _joel 1 hour ago
        I'm all for using a council of LLMs, I wrote a tool for it https://github.com/joelio/owl - but you still need to read through PRs yourself, at the very least.
      • acedTrex 1 hour ago
        It's not actually, thats just shoving more shit into the shit pipeline.

        Humans need to review this stuff yall there's no way around that, apparently to some, very inconvenient reality.

        • devin 1 hour ago
          It’s clear that they want this to be true so bad that they’re just not going to do it, and will spend a ton of money on quality gates and mitigation strategies instead of just reading some code.
    • Twirrim 2 hours ago
      You can't rely on people spotting the significance of such changes
      • eithed 1 hour ago
        Tests would have caught it = https://github.com/rhysd/actionlint injection check
      • dv_dt 1 hour ago
        I have been talking to people who want to autoreview and autoapprove "minor" AI prs. For security especially, I think if the models weren't enough to prevent the issues, they aren't enough to judge what is minor.
      • fn-mote 2 hours ago
        ^^

        Absolutely.

        Nothing in the PR jumps out as a red flag. Unless you know how the internals work, I suppose.

        • larsonian 1 hour ago
          Are you kidding? It's a very obvious case of quote injection. Not some subtle race condition or anything.
          • joombaga 35 minutes ago
            I think it's obvious too. I'd call out any case of `${{ }}` interpolation in a `run` block, and it's something I watch for in PRs. I also know other people don't watch for this, as I've corrected it about a hundred times. Over the last 10 years my average colleague understands less and less about injection or to watch for it at layer boundaries.
        • chrisjj 1 hour ago
          > Nothing in the PR jumps out as a red flag.

          Made by AI?

  • beyondscale-sha 9 minutes ago
    [dead]
  • mhrsntrk 1 hour ago
    [flagged]
  • antiloper 1 hour ago
    Someone forgot to add "make no mistakes!" when triggering autofix /s