Paper published in a book (Scientific congresses and symposiums)
Mitigating Security Issues in GitHub Actions
Onsori delicheh, Hassan; Mens, Tom
2024In 2024 ACM/IEEE 4th International Workshop on Engineering and Cybersecurity of Critical Systems (EnCyCriS) and 2024 IEEE/ACM Second International Workshop on Software Vulnerability (EnCyCriS/SVM '24)
Peer reviewed
 

Files


Full Text
Hassan2024-EnCyCriSSVM.pdf
Author postprint (464.67 kB)
Owner grants to ACM an exclusive, worldwide, royalty-free, perpetual, irrevocable, transferable and sublicenseable license to publish, reproduce and distribute all or any part of the Work in any and all forms of media, now or hereafter known, including in the above publication and in the ACM Digital Library, and to authorize third parties to do the same.
Download

All documents in ORBi UMONS are protected by a user license.

Send to



Details



Keywords :
GitHub Actions; collaborative software development; workflow automation; security risk; software supply chain
Abstract :
[en] Collaborative practices have revolutionised the software development process, enabling distributed teams to seamlessly work together. Social coding platforms have integrated CI/CD automation workflows, with GitHub Actions emerging as a prominent automation ecosystem for GitHub repositories. While automation brings efficiency, it also introduces security challenges, often related to software supply chain attacks and workflow misconfigurations. We outline the security issues associated with the software supply chain of GitHub Actions workflows, most notably their reusable Actions and their dependencies. We also explore the security risks associated with misconfigurations of repositories and workflows, such as poor permission management, command injection, and credential exposure. To mitigate these risks we suggest practical remediations, including dependency and security monitoring, pinning Actions, strict access control, verified creator practices, secret scanning tools, raising awareness, and training. In doing so, we provide valuable insights on the need to integrate security seamlessly into the automated collaborative software development processes. To enhance the security of workflow automation within GitHub repositories we encourage a proactive approach and advocate for the adoption of best practices.
Disciplines :
Computer science
DOI :
10.1145/3643662.3643961
Author, co-author :
Onsori delicheh, Hassan  ;  Université de Mons - UMONS > Faculté des Science > Service de Génie Logiciel
Mens, Tom  ;  Université de Mons - UMONS > Faculté des Sciences > Service de Génie Logiciel
Language :
English
Title :
Mitigating Security Issues in GitHub Actions
Publication date :
15 April 2024
Event name :
2024 ACM/IEEE 4th International Workshop on Engineering and Cybersecurity of Critical Systems (EnCyCriS) and 2024 IEEE/ACM 2nd International Workshop on Software Vulnerability
Event organizer :
ACM/IEEE
Event place :
Lisbon, Portugal
Event date :
April 15, 2024
Audience :
International
Main work title :
2024 ACM/IEEE 4th International Workshop on Engineering and Cybersecurity of Critical Systems (EnCyCriS) and 2024 IEEE/ACM Second International Workshop on Software Vulnerability (EnCyCriS/SVM '24)
Publisher :
ACM/IEEE
ISBN/EAN :
979-8-4007-0565-6
Pages :
6
Peer reviewed :
Peer reviewed
Research unit :
S852 - Génie Logiciel
Research institute :
R300 - Institut de Recherche en Technologies de l'Information et Sciences de l'Informatique
Funders :
F.R.S.-FNRS - Fonds de la Recherche Scientifique [BE]
Funding number :
T.0149.22; J.0147.24
Funding text :
This research is supported by the Fonds de la Recherche Scientifique - FNRS under grant numbers T.0149.22 and J.0147.24.
Commentary :
© Hassan Onsori Delicheh, Tom Mens, 2024. This is the author's version of the work. It is posted here for your personal use. Not for redistribution. The definitive version was published in Proceedings of EnCyCriS/SVM '24: 2024 ACM/IEEE 4th International Workshop on Engineering and Cybersecurity of Critical Systems (EnCyCriS) and 2024 IEEE/ACM Second International Workshop on Software Vulnerability, https://doi.org/10.1145/3643662.3643961
Available on ORBi UMONS :
since 01 February 2024

Statistics


Number of views
38 (12 by UMONS)
Number of downloads
173 (11 by UMONS)

Bibliography


Similar publications



Contact ORBi UMONS