
Security-research lab reproducing CVE-2021-4281 (GHSA-3796-3f93-cfvx): shell command injection via PR head-branch name in .github/workflows/combine-prs.yml (snapshot of BraveUX/for-the-badge @ 409c1fda). Do not use; authorized reproduction only.
Automated research artifact — not the upstream project.
This repository is a disposable lab built by an automated harness for a master's thesis at Université Laval on reproducing published GitHub Actions workflow vulnerabilities. It is a verbatim snapshot of
BraveUX/for-the-badgeat commit409c1fda3477b8dd05f3289926e08d88edd5a664(2021-07-20), redistributed under that project's own licence.The upstream project is not involved, is never targeted, and the vulnerability studied here is already public. Every secret and variable in this repository is a randomly generated dummy value — no real credential is present. Action references and runner images are pinned to what they resolved to on 2021-07-20; see
pinning.mdin the harness output for every change made to the snapshot.Questions or objections: [email protected]
# For the Badge
We don't develop for the money, power, fame, or codebabes. We do it For the Badge. It all started because of an obsession with two words: . It all ended with this: .
Interested in having a badge submitted to the general site? Submit a pull request of the badge you'd like to see added and provide a Share Badge link generated from our For The Badge Generator.
Not all badges will be accepted but if there is enough community excitement behind a badge or if we just really like it, we'll add it to the growing list of badges!
Interested in learning more or seeing the code behind the Badge Generator? Check out the repo here.
The Copy Markdown output is in Base64 so as to not need the badge to be hosted anywhere. This unfortunately means that it will not render in many markdown programs due to security issues, though there have been numerous submissions to account for this. Nonetheless, should you wish to include one of these badges in your own markdown where it fails to support Base64, I suggest you download the badge, and then upload it to the project you wish for it to render in. It's a minor inconvenience, but it sure is better than nothing.
Not good enough? Well you could also submit a pull request for the badge to be hosted on our For The Badge site.