
Authorized security-research reproduction lab for CVE-2025-54415 (GHSA-g5hx-xv45-9whg): astronomer/dag-factory snapshot at 464c75a — pull_request_target head-SHA checkout executes attacker-controlled hatch scripts in base-repo context
Automated research artifact — not the upstream project.
This repository is a disposable lab built by an automated harness for a master's thesis at Université Laval on reproducing published GitHub Actions workflow vulnerabilities. It is a verbatim snapshot of
astronomer/dag-factoryat commit464c75ad8676e930f5ffd848312b7969b96844d7(2025-07-04), redistributed under that project's own licence, whose file is included unchanged in this snapshot.The upstream project is not involved, is never targeted, and the vulnerability studied here is already public. Every secret and variable in this repository is a randomly generated dummy value — no real credential is present. Action references and runner images are pinned to what they resolved to on 2025-07-04; see
pinning.mdin the harness output for every change made to the snapshot.Questions or objections: [email protected]

Welcome to dag-factory! dag-factory is a library for Apache Airflow® to construct DAGs declaratively via configuration files.
The minimum requirements for dag-factory are:
For a gentle introduction, please take a look at our Quickstart Guide. For more examples, please see the examples folder.
To learn more about the terms and conditions for use, reproduction and distribution, read the Apache License 2.0.
This project follows Astronomer's Privacy Policy.
For further information, read this
Check the project's Security Policy to learn how to report security vulnerabilities in DAG Factory and how security issues reported to the DAG Factory security team are handled.