Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(security): PR Previews from Forks #110

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

AdrianGonz97
Copy link

The Issue

Hey! I'm the maintainer of the Github Action refined-cf-pages-action and we were recently made aware of a security vulnerability regarding the pull_request_target workflow event where it's possible to leak secrets (including the CF credentials used in the action) through a Github Actions exploit when running untrusted code. Unfortunately, our previous recommendation for the setup of the PR Previews from Forks feature included the use of this workflow event type without PR approvals, which has now been updated.

I'm going around to all of the dependents of the action that are using the PR Previews from Forks feature to apply the fix.

The Fix

We've come up with an alternate method that is safer to use and will resolve this issue entirely.

Rather than using pull_request_target, which runs in a privileged environment (meaning that repository secrets can be used in it), previews will now be deployed in two stages:

  1. The first stage (build-preview.yml) will use the pull_request event, which runs in an unprivileged environment, making it safe to run untrusted code. The site will be built in this stage and the build directory will be uploaded to Github as an artifact.
  2. The second stage (deploy-preview.yml) will use the workflow_run event, which runs in a privileged environment where its only job will be to download the build artifact and then run the refined-cf-pages-action action to upload the build files to Cloudflare Pages for preview deployment.

And that's it! No further actions are necessary.

Thanks for your time!

Copy link

github-actions bot commented Aug 3, 2024

built with Refined Cloudflare Pages Action

⚡ Cloudflare Pages Deployment

Name Status Preview Last Commit
papermc-website 🔨 Building (View Log) 1e3609d

@PaperMC PaperMC deleted a comment from vercel bot Aug 6, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant