
Octoscan은 GitHub Actions 워크플로우를 위한 정적 취약점 스캐너입니다.
Octoscan은 GitHub Action 워크플로우를 위한 정적 취약점 스캐너입니다.
$ go mod tidy
$ go build
또는 docker로:
$ docker pull ghcr.io/synacktiv/octoscan:latest
Octoscan은 로컬 git 저장소를 대상으로 실행하거나 dl 액션으로 모든 워크플로우를 다운로드할 수 있습니다:
$ octoscan dl -h
Octoscan.
Usage:
octoscan dl [options] --org <org> [--repo <repo> --token <pat> --default-branch --max-branches <num> --path <path> --output-dir <dir> --include-archives]
Options:
-h, --help Show help
-d, --debug Debug output
--verbose Verbose output
--org <org> Organizations to target
--repo <repo> Repository to target
--token <pat> GHP to authenticate to GitHub
--default-branch Only download workflows from the default branch
--max-branches <num> Limit the number of branches to download
--path <path> GitHub file path to download [default: .github/workflows]
--output-dir <dir> Output dir where to download files [default: octoscan-output]
--include-archives Also download archived repositories
./octoscan dl --token ghp_<token> --org apache --repo incubator-answer
무엇을 실행해야 할지 모르겠다면 그냥 다음을 실행하세요:
./octoscan scan path/to/repos/ --disable-rules shellcheck,local-action --filter-triggers external
이러면 오탐(false positive)이 줄어들고 가장 흥미로운 결과를 얻을 수 있습니다.
dl 명령으로 워크플로우를 다운로드한 경우, 기본적으로 octoscan은 모든 브랜치의 모든 워크플로우를 다운로드하므로 중복된 워크플로우가 생길 수 있습니다. 중복된 워크플로우를 삭제하고 분석 속도를 높이려면 분석을 실행하기 전에 fdupes 명령을 사용할 수 있습니다:
fdupes -n -r -N -d path/to/repo
$ octoscan scan -h
octoscan
Usage:
octoscan scan [options] --list-rules
octoscan scan [options] <target>
octoscan scan [options] <target> [--debug-rules --filter-triggers=<triggers> --filter-run --ignore=<pattern> ((--disable-rules | --enable-rules ) <rules>) --config-file <config>]
Options:
-h, --help
-v, --version
-d, --debug
--verbose
--format <format> Output format, json, sarif or custom template to format error messages in Go template syntax. See https://github.com/rhysd/actionlint/tree/main/docs/usage.md#format
--oneline Use one line per one error. Useful for reading error messages from programs
Args:
<target> Target File or directory to scan
--filter-triggers <triggers> Scan workflows with specific triggers (comma separated list: "push,pull_request_target" or pre-configured: external/allnopr)
--filter-run Search for expression injection only in run shell scripts.
--ignore <pattern> Regular expression matching to error messages you want to ignore.
--disable-rules <rules> Disable specific rules. Split on ","
--enable-rules <rules> Enable specific rules, this will disable all other rules. Split on ","
--debug-rules Enable debug rules.
--config-file <config> Config file.
Examples:
$ octoscan scan ci.yml --disable-rules shellcheck,local-action --filter-triggers external
이 도구는 GitHub Action으로 직접 사용하여 push/pull_request 이벤트에서 저장소를 스캔할 수도 있습니다. 자세한 내용은 이 저장소를 확인하세요.
전체 규칙 목록은 다음 명령으로 확인할 수 있습니다:
$ octoscan scan --list-rules
2024/08/07 16:50:48 [INFO] Available rules
- shellcheck
Checks for shell script sources in "run:" using shellcheck
- credentials
Checks for credentials in "services:" configuration
- dangerous-action
Check for dangerous actions.
- dangerous-checkout
Check for dangerous checkout.
- expression-injection
Check for expression injection.
- dangerous-write
Check for dangerous write operation on $GITHUB_OUTPUT or $GITHUB_ENV.
- local-action
Check for local actions.
- runner-label
Checks for GitHub-hosted and preset self-hosted runner labels in "runs-on:"
- unsecure-commands
Check 'ACTIONS_ALLOW_UNSECURE_COMMANDS' env variable.
- known-vulnerability
Check for known vulnerabilities.
- bot-check
Check for if statements that are based on a bot identity.
- dangerous-artefact
Check for workflow that upload artefacts containing sensitive files.
- debug-external-trigger
Check for workflow that can be externally triggered.
- debug-artefacts
Check for workflow that upload artefacts.
- debug-js-exec
Check for workflow that execute system commands in JS scripts.
- debug-oidc-action
Check for OIDC actions.
- repo-jacking
Verify that external actions are pointing to a valid GitHub user or organization.
workflow_run 또는 pull_request_target 같은 트리거는 비밀(secret)에 대한 읽기 권한과 대상 저장소에 대한 잠재적 쓰기 권한을 가지므로 권한 있는 컨텍스트에서 실행됩니다. 이러한 컨텍스트에서 신뢰할 수 없는 코드를 명시적으로 체크아웃하면 공격자 코드가 다운로드되는 결과가 발생합니다.

이 규칙은 위험한 액션이 사용될 경우 사용자에게 경고합니다. 주로 신뢰할 수 없는 아티팩트(artifact)에 초점을 맞춥니다.
서로 다른 워크플로우 간에 데이터를 전달하기 위해 아티팩트를 사용하는 것은 일반적인 관행입니다. 이는 트리거링 워크플로우가 일부 데이터를 준비한 다음 트리거된 워크플로우로 보내는 workflow_run 트리거에서 자주 발견됩니다. 이 아티팩트 데이터는 신뢰할 수 없는 특성을 가지므로 주의를 기울여 처리하고 잠재적 위협으로 인식하는 것이 중요합니다. 취약점은 악의적인 행위자와 같은 외부 개체가 아티팩트 데이터의 콘텐츠에 영향을 미칠 수 있다는 사실에서 발생합니다.

GitHub은 워크플로우의 모든 단계에서 사용할 수 있는 기본 환경 변수를 생성합니다. GITHUB_ENV 및 GITHUB_OUTPUT 변수는 특히 흥미롭습니다. 한 단계에서 환경 변수를 정의하고 다른 단계에서 이 변수를 사용할 수 있습니다. 이는 연결된 변수에 값을 작성하여 수행할 수 있습니다. 사용자가 설정되는 변수의 콘텐츠를 제어할 수 있다면 이는 임의 코드 실행으로 이어질 수 있습니다.
