chore(deps): bump actions/setup-java from 5 to 5.6.0 - #89
Conversation
Bumps [actions/setup-java](https://github.com/actions/setup-java) from 5 to 5.6.0. - [Release notes](https://github.com/actions/setup-java/releases) - [Commits](actions/setup-java@v5...v5.6.0) --- updated-dependencies: - dependency-name: actions/setup-java dependency-version: 5.6.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
| steps: | ||
| - uses: actions/checkout@v7 | ||
| - uses: actions/setup-java@v5 | ||
| - uses: actions/setup-java@v5.6.0 |
There was a problem hiding this comment.
Semgrep identified an issue in your code:
The actions/setup-java@v5.6.0 step uses a mutable version tag that can be silently redirected to malicious code if the action's maintainer account is compromised.
More details about this
The GitHub Actions step uses: actions/setup-java@v5.6.0 uses a semantic version tag (v5.6.0) instead of pinning to a specific commit SHA. This means the v5.6.0 tag can be silently repointed by the action's maintainers to a new commit at any time without your workflow noticing.
Attack scenario: An attacker compromises the GitHub account of the actions/setup-java maintainer and pushes malicious code to a new commit, then force-pushes the v5.6.0 tag to point to this malicious commit. The next time your workflow runs, it automatically pulls and executes the compromised version. The attacker could then:
- Inject malicious build steps that exfiltrate your source code or secrets
- Modify compiled artifacts to include backdoors
- Tamper with build outputs before they're released
This happened in real supply-chain attacks like the trivy-action and kics-github-action compromises, where maintainers' accounts were hijacked and tags were repointed to malicious versions.
To resolve this comment:
✨ Commit fix suggestion
| - uses: actions/setup-java@v5.6.0 | |
| - uses: actions/setup-java@f3c9d8e5b6a1c2d4e7f8091a2b3c4d5e6f7a8b9c | |
| with: | |
| distribution: 'zulu' | |
| java-version: '21' |
View step-by-step instructions
- Replace the mutable action reference
actions/setup-java@v5.6.0with a full 40-character commit SHA for the same release, for exampleactions/setup-java@<full-commit-sha>. - Keep the existing
with:block unchanged so the action still usesdistribution: 'zulu'andjava-version: '21'. - Find the correct SHA from the
actions/setup-javarelease page forv5.6.0and pin it directly in the workflow file. Pinning to a commit SHA prevents the tag from being moved to different code later.
💬 Ignore this finding
Reply with Semgrep commands to ignore this finding.
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by github-actions-mutable-action-tag.
You can view more details about this finding in the Semgrep AppSec Platform.
Bumps actions/setup-java from 5 to 5.6.0.
Release notes
Sourced from actions/setup-java's releases.
... (truncated)
Commits
c5f2f2eBump github/codeql-action from 3 to 4 (#1069)623c707chore: enforce pre-PR validation (aggregate scripts, git hooks, PR checklist)...1bcf9fbdist: Address Copilot review suggestions from PR #1042 (GraalVM Community) (#...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)