
Security-research lab reproducing CVE-2026-39382 (GHSA-5jxf-vmqr-5g82): command injection in dbt-labs reusable workflow open-issue-in-repo.yml, driven by a dbt-core-style docs-issue.yml caller
Automated research artifact — not the upstream project.
This repository is a disposable lab built by an automated harness for a master's thesis at Université Laval on reproducing published GitHub Actions workflow vulnerabilities. It is a verbatim snapshot of
dbt-labs/actionsat commited19ee39fd410f9ebc3ef202a8c80879a3328697(2026-04-01), redistributed under that project's own licence, whose file is included unchanged in this snapshot.The upstream project is not involved, is never targeted, and the vulnerability studied here is already public. Every secret and variable in this repository is a randomly generated dummy value — no real credential is present. Action references and runner images are pinned to what they resolved to on 2026-04-01; see
pinning.mdin the harness output for every change made to the snapshot.Questions or objections: [email protected]
A set of GitHub Actions and Reusable Workflows for automating common tasks related to developing, maintaining, and testing dbt-core, database adapter plugins, and other dbt-labs open source projects.
Actions and workflows should be self documented. See individual actions for more info and instructions on how to use.
Changelog Handling
Scheduled Installation Tests
Generic Shared Workflows
Jira Issue Syncing - used by dbt-metrics
Everyone interacting in the project's codebases, issue trackers, chat rooms, and mailing lists is expected to follow the dbt Code of Conduct.