fix: revert security-scan.yml to inline, not a reusable-workflow call #20

Merged
james merged 1 commit from fix/inline-security-scan into main 2026-09-07 20:13:07 +00:00
Owner

Calling forgejo-workflows' shared security-scan reusable workflow silently broke ojo-forgejo's PR comments: they posted on every PR through #12, and on zero PRs since #13 -- the exact commit that converted this to uses:. No visibility into forgejo-runner internals to know exactly why a nested custom action loses the PR context when invoked through a reusable workflow, but the correlation is total across 7+ PRs since. Reverting to the known-working inline form.

renovate.yml is unaffected (it never posts PR comments) and stays on the shared workflow.

Calling `forgejo-workflows`' shared security-scan reusable workflow silently broke `ojo-forgejo`'s PR comments: they posted on every PR through #12, and on zero PRs since #13 -- the exact commit that converted this to `uses:`. No visibility into `forgejo-runner` internals to know exactly why a nested custom action loses the PR context when invoked through a reusable workflow, but the correlation is total across 7+ PRs since. Reverting to the known-working inline form. `renovate.yml` is unaffected (it never posts PR comments) and stays on the shared workflow.
fix: revert security-scan.yml to inline, not a reusable-workflow call
Some checks failed
security-scan / security-scan (pull_request) Successful in 25s
test / go (pull_request) Has been cancelled
test / web (pull_request) Has been cancelled
2630af9b6d
Calling forgejo-workflows' shared security-scan reusable workflow
silently broke ojo-forgejo's PR comments: they posted on every PR
through #12, and on zero PRs since #13 -- the exact commit that
converted this to uses:. No visibility into forgejo-runner internals to
know why a nested custom action loses the PR context when invoked
through a reusable workflow, but the correlation is total across 7+
PRs. Reverting to the known-working inline form; renovate.yml is
unaffected (it never posts PR comments) and stays on the shared
workflow.

🔎 ojo scan results

Severity Count
🟠 HIGH 14
🟡 MEDIUM 7
🟢 LOW 5
⚪ UNKNOWN 5
Details (31)
Type Severity ID/Rule Location Description
vuln 🟠 HIGH CVE-2026-33487 github.com/russellhaering/[email protected] validateSignature Loop Variable Capture Signature Bypass in goxmldsig
vuln 🟠 HIGH CVE-2026-73088 [email protected] Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats)
vuln 🟠 HIGH CVE-2026-73089 [email protected] Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM
vuln 🟠 HIGH CVE-2026-67213 [email protected] nanoid: custom generators can loop indefinitely when size is zero
secret 🟠 HIGH db-connection-string README.md:28 Database connection string with embedded password detected
secret 🟠 HIGH db-connection-string deploy/docker/docker-compose.yml:29 Database connection string with embedded password detected
secret 🟠 HIGH db-connection-string deploy/k8s/00-namespace-config.yaml:17 Database connection string with embedded password detected
sast 🟠 HIGH go-ssrf internal/auth/saml_test.go:325 http.Get URL argument is built via Sprintf/concatenation, or is a local variable derived from request/env input, rather than a validated/allowlisted URL
sast 🟠 HIGH go-ssrf internal/integrations/jira.go:43 http.NewRequestWithContext URL argument is built via Sprintf/concatenation, or is a local variable derived from request/env input, rather than a validated/allowlisted URL
sast 🟠 HIGH go-ssrf internal/integrations/jira.go:73 http.NewRequestWithContext URL argument is built via Sprintf/concatenation, or is a local variable derived from request/env input, rather than a validated/allowlisted URL
sast 🟠 HIGH go-ssrf internal/integrations/jira.go:109 http.NewRequestWithContext URL argument is built via Sprintf/concatenation, or is a local variable derived from request/env input, rather than a validated/allowlisted URL
sast 🟠 HIGH js-ssrf web/src/lib/api.ts:39 fetch(...) URL argument is derived from request/env input (directly, or through a local variable) or built via template-literal interpolation/concatenation rather than a validated/allowlisted URL
sast 🟠 HIGH js-ssrf web/src/lib/api.ts:64 fetch(...) URL argument is derived from request/env input (directly, or through a local variable) or built via template-literal interpolation/concatenation rather than a validated/allowlisted URL
sast 🟠 HIGH js-ssrf web/src/lib/api.ts:95 fetch(...) URL argument is derived from request/env input (directly, or through a local variable) or built via template-literal interpolation/concatenation rather than a validated/allowlisted URL
misconfig 🟡 MEDIUM k8s-run-as-root deploy/k8s/10-postgres.yaml:1 container postgres
misconfig 🟡 MEDIUM k8s-run-as-root deploy/k8s/20-api.yaml:1 container api
misconfig 🟡 MEDIUM k8s-run-as-root deploy/k8s/30-web.yaml:1 container web
sast 🟡 MEDIUM go-open-redirect internal/api/handlers/oidc_handler.go:50 http.Redirect target is derived from request input (directly or through a local variable) or built via Sprintf/concatenation rather than a literal/allowlisted URL
sast 🟡 MEDIUM go-open-redirect internal/api/handlers/oidc_handler.go:99 http.Redirect target is derived from request input (directly or through a local variable) or built via Sprintf/concatenation rather than a literal/allowlisted URL
sast 🟡 MEDIUM go-open-redirect internal/api/handlers/saml_handler.go:54 http.Redirect target is derived from request input (directly or through a local variable) or built via Sprintf/concatenation rather than a literal/allowlisted URL
sast 🟡 MEDIUM go-open-redirect internal/api/handlers/saml_handler.go:95 http.Redirect target is derived from request input (directly or through a local variable) or built via Sprintf/concatenation rather than a literal/allowlisted URL
misconfig 🟢 LOW dockerfile-no-healthcheck deploy/docker/Dockerfile:1 image has no HEALTHCHECK
misconfig 🟢 LOW dockerfile-no-healthcheck deploy/docker/Dockerfile.web:1 image has no HEALTHCHECK
misconfig 🟢 LOW k8s-missing-resource-limits deploy/k8s/10-postgres.yaml:1 container postgres can consume unbounded CPU/memory
sast 🟢 LOW go-cookie-missing-flags internal/api/handlers/auth_handlers.go:42 http.Cookie{...} doesn't set Secure; it defaults to false, weakening cookie protection unless set elsewhere
sast 🟢 LOW go-cookie-missing-flags internal/api/handlers/auth_handlers.go:52 http.Cookie{...} doesn't set Secure; it defaults to false, weakening cookie protection unless set elsewhere
vuln ⚪ UNKNOWN GO-2026-5932 golang.org/x/[email protected] The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
vuln ⚪ UNKNOWN CVE-2026-56854 golang.org/x/[email protected] Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh
vuln ⚪ UNKNOWN CVE-2026-78662 golang.org/x/[email protected] Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh
vuln ⚪ UNKNOWN CVE-2026-56855 golang.org/x/[email protected] Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh
vuln ⚪ UNKNOWN CVE-2026-56852 golang.org/x/[email protected] Infinite loop on invalid input in golang.org/x/text
<!-- ojo-scan-summary --> ### 🔎 ojo scan results | Severity | Count | |---|---| | 🟠 HIGH | 14 | | 🟡 MEDIUM | 7 | | 🟢 LOW | 5 | | ⚪ UNKNOWN | 5 | <details><summary>Details (31)</summary> | Type | Severity | ID/Rule | Location | Description | |---|---|---|---|---| | vuln | 🟠 HIGH | <a href="https://github.com/russellhaering/goxmldsig/security/advisories/GHSA-479m-364c-43vc" target="_blank" rel="noopener noreferrer">CVE-2026-33487</a> | github.com/russellhaering/[email protected] | validateSignature Loop Variable Capture Signature Bypass in goxmldsig | | vuln | 🟠 HIGH | <a href="https://github.com/browserslist/browserslist/security/advisories/GHSA-73wf-gq98-2v4g" target="_blank" rel="noopener noreferrer">CVE-2026-73088</a> | [email protected] | Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats) | | vuln | 🟠 HIGH | <a href="https://github.com/browserslist/browserslist/security/advisories/GHSA-c83g-rgw3-j3cx" target="_blank" rel="noopener noreferrer">CVE-2026-73089</a> | [email protected] | Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM | | vuln | 🟠 HIGH | <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-67213" target="_blank" rel="noopener noreferrer">CVE-2026-67213</a> | [email protected] | nanoid: custom generators can loop indefinitely when size is zero | | secret | 🟠 HIGH | db-connection-string | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/e83b383603be5a5b719a0da41ab4952f01379df4/README.md#L28" target="_blank" rel="noopener noreferrer">README.md:28</a> | Database connection string with embedded password detected | | secret | 🟠 HIGH | db-connection-string | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/e83b383603be5a5b719a0da41ab4952f01379df4/deploy/docker/docker-compose.yml#L29" target="_blank" rel="noopener noreferrer">deploy/docker/docker-compose.yml:29</a> | Database connection string with embedded password detected | | secret | 🟠 HIGH | db-connection-string | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/e83b383603be5a5b719a0da41ab4952f01379df4/deploy/k8s/00-namespace-config.yaml#L17" target="_blank" rel="noopener noreferrer">deploy/k8s/00-namespace-config.yaml:17</a> | Database connection string with embedded password detected | | sast | 🟠 HIGH | go-ssrf | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/e83b383603be5a5b719a0da41ab4952f01379df4/internal/auth/saml_test.go#L325" target="_blank" rel="noopener noreferrer">internal/auth/saml_test.go:325</a> | http.Get URL argument is built via Sprintf/concatenation, or is a local variable derived from request/env input, rather than a validated/allowlisted URL | | sast | 🟠 HIGH | go-ssrf | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/e83b383603be5a5b719a0da41ab4952f01379df4/internal/integrations/jira.go#L43" target="_blank" rel="noopener noreferrer">internal/integrations/jira.go:43</a> | http.NewRequestWithContext URL argument is built via Sprintf/concatenation, or is a local variable derived from request/env input, rather than a validated/allowlisted URL | | sast | 🟠 HIGH | go-ssrf | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/e83b383603be5a5b719a0da41ab4952f01379df4/internal/integrations/jira.go#L73" target="_blank" rel="noopener noreferrer">internal/integrations/jira.go:73</a> | http.NewRequestWithContext URL argument is built via Sprintf/concatenation, or is a local variable derived from request/env input, rather than a validated/allowlisted URL | | sast | 🟠 HIGH | go-ssrf | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/e83b383603be5a5b719a0da41ab4952f01379df4/internal/integrations/jira.go#L109" target="_blank" rel="noopener noreferrer">internal/integrations/jira.go:109</a> | http.NewRequestWithContext URL argument is built via Sprintf/concatenation, or is a local variable derived from request/env input, rather than a validated/allowlisted URL | | sast | 🟠 HIGH | js-ssrf | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/e83b383603be5a5b719a0da41ab4952f01379df4/web/src/lib/api.ts#L39" target="_blank" rel="noopener noreferrer">web/src/lib/api.ts:39</a> | fetch(...) URL argument is derived from request/env input (directly, or through a local variable) or built via template-literal interpolation/concatenation rather than a validated/allowlisted URL | | sast | 🟠 HIGH | js-ssrf | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/e83b383603be5a5b719a0da41ab4952f01379df4/web/src/lib/api.ts#L64" target="_blank" rel="noopener noreferrer">web/src/lib/api.ts:64</a> | fetch(...) URL argument is derived from request/env input (directly, or through a local variable) or built via template-literal interpolation/concatenation rather than a validated/allowlisted URL | | sast | 🟠 HIGH | js-ssrf | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/e83b383603be5a5b719a0da41ab4952f01379df4/web/src/lib/api.ts#L95" target="_blank" rel="noopener noreferrer">web/src/lib/api.ts:95</a> | fetch(...) URL argument is derived from request/env input (directly, or through a local variable) or built via template-literal interpolation/concatenation rather than a validated/allowlisted URL | | misconfig | 🟡 MEDIUM | k8s-run-as-root | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/e83b383603be5a5b719a0da41ab4952f01379df4/deploy/k8s/10-postgres.yaml#L1" target="_blank" rel="noopener noreferrer">deploy/k8s/10-postgres.yaml:1</a> | container postgres | | misconfig | 🟡 MEDIUM | k8s-run-as-root | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/e83b383603be5a5b719a0da41ab4952f01379df4/deploy/k8s/20-api.yaml#L1" target="_blank" rel="noopener noreferrer">deploy/k8s/20-api.yaml:1</a> | container api | | misconfig | 🟡 MEDIUM | k8s-run-as-root | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/e83b383603be5a5b719a0da41ab4952f01379df4/deploy/k8s/30-web.yaml#L1" target="_blank" rel="noopener noreferrer">deploy/k8s/30-web.yaml:1</a> | container web | | sast | 🟡 MEDIUM | go-open-redirect | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/e83b383603be5a5b719a0da41ab4952f01379df4/internal/api/handlers/oidc_handler.go#L50" target="_blank" rel="noopener noreferrer">internal/api/handlers/oidc_handler.go:50</a> | http.Redirect target is derived from request input (directly or through a local variable) or built via Sprintf/concatenation rather than a literal/allowlisted URL | | sast | 🟡 MEDIUM | go-open-redirect | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/e83b383603be5a5b719a0da41ab4952f01379df4/internal/api/handlers/oidc_handler.go#L99" target="_blank" rel="noopener noreferrer">internal/api/handlers/oidc_handler.go:99</a> | http.Redirect target is derived from request input (directly or through a local variable) or built via Sprintf/concatenation rather than a literal/allowlisted URL | | sast | 🟡 MEDIUM | go-open-redirect | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/e83b383603be5a5b719a0da41ab4952f01379df4/internal/api/handlers/saml_handler.go#L54" target="_blank" rel="noopener noreferrer">internal/api/handlers/saml_handler.go:54</a> | http.Redirect target is derived from request input (directly or through a local variable) or built via Sprintf/concatenation rather than a literal/allowlisted URL | | sast | 🟡 MEDIUM | go-open-redirect | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/e83b383603be5a5b719a0da41ab4952f01379df4/internal/api/handlers/saml_handler.go#L95" target="_blank" rel="noopener noreferrer">internal/api/handlers/saml_handler.go:95</a> | http.Redirect target is derived from request input (directly or through a local variable) or built via Sprintf/concatenation rather than a literal/allowlisted URL | | misconfig | 🟢 LOW | dockerfile-no-healthcheck | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/e83b383603be5a5b719a0da41ab4952f01379df4/deploy/docker/Dockerfile#L1" target="_blank" rel="noopener noreferrer">deploy/docker/Dockerfile:1</a> | image has no HEALTHCHECK | | misconfig | 🟢 LOW | dockerfile-no-healthcheck | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/e83b383603be5a5b719a0da41ab4952f01379df4/deploy/docker/Dockerfile.web#L1" target="_blank" rel="noopener noreferrer">deploy/docker/Dockerfile.web:1</a> | image has no HEALTHCHECK | | misconfig | 🟢 LOW | k8s-missing-resource-limits | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/e83b383603be5a5b719a0da41ab4952f01379df4/deploy/k8s/10-postgres.yaml#L1" target="_blank" rel="noopener noreferrer">deploy/k8s/10-postgres.yaml:1</a> | container postgres can consume unbounded CPU/memory | | sast | 🟢 LOW | go-cookie-missing-flags | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/e83b383603be5a5b719a0da41ab4952f01379df4/internal/api/handlers/auth_handlers.go#L42" target="_blank" rel="noopener noreferrer">internal/api/handlers/auth_handlers.go:42</a> | http.Cookie{...} doesn't set Secure; it defaults to false, weakening cookie protection unless set elsewhere | | sast | 🟢 LOW | go-cookie-missing-flags | <a href="https://git.colibrisec.org/ColibriSec/balam/src/commit/e83b383603be5a5b719a0da41ab4952f01379df4/internal/api/handlers/auth_handlers.go#L52" target="_blank" rel="noopener noreferrer">internal/api/handlers/auth_handlers.go:52</a> | http.Cookie{...} doesn't set Secure; it defaults to false, weakening cookie protection unless set elsewhere | | vuln | ⚪ UNKNOWN | <a href="https://go.dev/issue/44226" target="_blank" rel="noopener noreferrer">GO-2026-5932</a> | golang.org/x/[email protected] | The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues | | vuln | ⚪ UNKNOWN | <a href="https://go.dev/issue/80213" target="_blank" rel="noopener noreferrer">CVE-2026-56854</a> | golang.org/x/[email protected] | Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh | | vuln | ⚪ UNKNOWN | <a href="https://go.dev/issue/81316" target="_blank" rel="noopener noreferrer">CVE-2026-78662</a> | golang.org/x/[email protected] | Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh | | vuln | ⚪ UNKNOWN | <a href="https://go.dev/issue/81317" target="_blank" rel="noopener noreferrer">CVE-2026-56855</a> | golang.org/x/[email protected] | Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh | | vuln | ⚪ UNKNOWN | <a href="https://go.dev/issue/80142" target="_blank" rel="noopener noreferrer">CVE-2026-56852</a> | golang.org/x/[email protected] | Infinite loop on invalid input in golang.org/x/text | </details>
james force-pushed fix/inline-security-scan from 2630af9b6d
Some checks failed
security-scan / security-scan (pull_request) Successful in 25s
test / go (pull_request) Has been cancelled
test / web (pull_request) Has been cancelled
to e83b383603
All checks were successful
security-scan / security-scan (pull_request) Successful in 23s
test / web (pull_request) Successful in 1m14s
test / go (pull_request) Successful in 1m22s
2026-09-07 20:03:37 +00:00
Compare
james merged commit 5aaba33552 into main 2026-09-07 20:13:07 +00:00
james deleted branch fix/inline-security-scan 2026-09-07 20:13:08 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
ColibriSec/balam!20
No description provided.