Fix a privilege escalation vulnerability and spam potential via untrusted code execution in the entropy scan. - #8262
Merged
Merged
Conversation
Replaced TruffleHog action with a Docker command to run it. Redirect output to be not leak secrets.
Refactor GitHub Actions workflow to create a sanitized summary of scan results and upload it. Adjust permissions and job structure for issue creation based on scan findings.
🐷 TruffleHog + Entropy Beauty ScanAverage entropy of changed code: 4.64 bits/char Changed files entropy: ✅ No secrets or suspicious high-entropy strings found. Mid-4 beauty heuristic in action — powered by our entropy chats! 😊 |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## 4.x #8262 +/- ##
============================================
- Coverage 98.59% 98.58% -0.02%
- Complexity 7143 7146 +3
============================================
Files 824 824
Lines 50768 50768
Branches 6905 6905
============================================
- Hits 50057 50048 -9
- Misses 485 489 +4
- Partials 226 231 +5 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Added caching for TruffleHog Docker image to optimize workflow.
🐷 TruffleHog + Entropy Beauty ScanAverage entropy of changed code: 4.651 bits/char Changed files entropy: ✅ No secrets or suspicious high-entropy strings found. Mid-4 beauty heuristic in action — powered by our entropy chats! 😊 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Previously, the attacker could have exfiltrated secrets, but only to spam the comments and perhaps social engineer more details out of us.
With help of Grok 4.5 super, in several steps, we fixed all the exfiltration paths.
Reported by https://github.com/August829