You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Control posture is adequate: zero secret alerts, daily CodeQL, threat-detection test suite (CTR-001–016), firewall v0.27.1, six security fixes merged in window.
Two critical unmitigated findings demand immediate action:
Cache-memory XPIA (#28830) — pentest-confirmed, score 24/25, no owner, no milestone, 7+ days open.
Unsafe quoting in compiler (CodeQL #600) — score 20/25, CRITICAL severity, no owner.
Systemic root: externally-influenced content flows into privileged execution contexts without sanitization — compiler → shell, cache → agent context, PR-ref → secrets-holding CI. On an AI-agent platform this converts to agent hijacking, credential theft, or unbounded spend.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
-
Repo:
github/gh-aw· Window: 2026-06-05→2026-06-12 · Run: §27428752211Signals: 472 commits (132 security-signal), 8 CodeQL alerts, 12 security issues, 0 secret scanning alerts.
Executive Summary
Control posture is
adequate: zero secret alerts, daily CodeQL, threat-detection test suite (CTR-001–016), firewall v0.27.1, six security fixes merged in window.Two critical unmitigated findings demand immediate action:
Systemic root: externally-influenced content flows into privileged execution contexts without sanitization — compiler → shell, cache → agent context, PR-ref → secrets-holding CI. On an AI-agent platform this converts to agent hijacking, credential theft, or unbounded spend.
Asset Tier Classification
setup_cache_memory_git.shpkg/workflow/awf_helpers.go.github/workflows/q.lock.ymlpkg/workflow/compilerenv/manager.goactions/setup/js/safe_outputs_handlers.cjspkg/workflow/cache.go+cache_integrity.go.github/workflows/dependabot-repair.lock.yml.github/workflows/aoai-endpoint-smoke-test.yml.github/workflows/error-message-lint.yml.github/workflows/dev-hawk.lock.ymlpkg/workflow/strings.goactions/setup/js/artifact_client.cjsactions/setup/js/apply_samples.cjs0 × A · 10 × B · 1 × C · 2 × D
Control Verification
govulncheckin go.mod but not in CI;sbom-actionnot SHA-pinnedMTTR proxy: 10–20 days · Ownership coverage: ~75%
Remediation Queue
Tier D — Critical (assign within 72 h, implement within 14 days)
git add -Ainsetup_cache_memory_git.sh(reject instruction-shaped patterns, quarantine to.gh-aw-quarantine/, emit::warning::). Add provenance sidecar per migration.fmt.Sprintf-into-shell callsites inawf_helpers.go; applyshellEscapeArgconsistently. Add go-linter rule to prevent regression.Tier C — High (14 days)
q.lock.yml—issue_commenttrigger queuesrepository_dispatch; privileged job checks out only default-branch ref. Remove 3poutine:ignoresuppressions after fix.Tier B — Medium/High (7–21 days)
int64return or bounds check inResolveDefaultTimeoutMinutes; audit allparsePositiveIntEnvVarcallers.@safe-outputs-exemptannotations; add CI gate.azure/login@v2to commit SHA; add permissions block toerror-message-lint.yml.Exception Register
poutine:ignore ×3q.lock.yml@safe-outputs-exempt SEC-005apply_samples.cjs:4@safe-outputs-exempt SEC-004artifact_client.cjs:5–6zizmor:ignore[github-env]dev-hawk.lock.yml:1718poutine:ignore ×3dependabot-repair.lock.ymlOperational Metrics Baseline
References: §27428752211 · #38795 Static Analysis · #28770 OWASP Top 10
Beta Was this translation helpful? Give feedback.
All reactions