Update pypa/gh-action-pypi-publish action to v1.13.0 [SECURITY] #84
No reviewers
Labels
No labels
bug
dependencies
documentation
duplicate
enhancement
good first issue
help wanted
invalid
python
question
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
dawid/rag-agent!84
Loading…
Reference in a new issue
No description provided.
Delete branch "renovate/github-tags-pypa-gh-action-pypi-publish-vulnerability"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
v1.12.4→v1.13.0GitHub Vulnerability Alerts
GHSA-vxmw-7h4f-hqxh
Summary
gh-action-pypi-publishmakes use of GitHub Actions expression expansions (i.e.${{ ... }}) in contexts that are potentially attacker controllable. Depending on the trigger used to invokegh-action-pypi-publish, this may allow an attacker to execute arbitrary code within the context of a workflow step that invokesgh-action-pypi-publish.Details
gh-action-pypi-publishcontains a composite action step,set-repo-and-ref, that makes use of expression expansions:Permalink:
github.com/pypa/gh-action-pypi-publish@db8f07d387/action.yml (L114-L125)In normal intended operation, these expansions are used to establish a correct priority for outputs like
refandrepo-id.However, these expansions have a side effect: because they're done with
${{ ... }}and not with${...}(i.e. normal shell interpolation), they can bypass normal shell quoting rules. In particular, if bothenv.ACTION_REFandenv.PR_REFevaluate to empty strings, then the expression falls back togithub.ref_name, which can be an attacker controlled string via a branch or tag name.For example, if the attacker is able to set a branch name to something like
innocent;cat${IFS}/etc/passwd, then theREFline may expand as:which would set
REFtoinnocentand then run the attacker's code.Additional information about dangerous expansions can be found in zizmor's
template-injectionrule documentation.Impact
The impact of this vulnerability is very low: the expression in question is unlikely to be evaluated in normal operation, since
env.ACTION_REFshould always take precedence.In particular, the action is not vulnerable in many popular configurations, i.e. those where
pull_requestorreleaseor apush: tagsevent is used to call the action.Release Notes
pypa/gh-action-pypi-publish (pypa/gh-action-pypi-publish)
v1.13.0Compare Source
Take the 2025 Python Packaging Survey if you still haven't!
✨ New Stuff
@woodruffw💰 updated the README to no longer mention the attestations feature being experimental in #347: it's been rather stable for a year already 🎉
He also added more diagnostic output which includes printing out the GitHub Environment claim via #371 and warning about the unsupported reusable workflows configurations #306, when using Trusted Publishing.
In addition to that, @konstin💰 sent #378 to pin
actions/setup-pythonto a SHA hash. This makespypi-publishcompatible with new GitHub policies that allow organizations to mandate hash-pinning actions used in workflows.🛠️ Internal Dependencies
@webknjaz💰 made a bunch of updates to the action runtime which includes bumping it to Python 3.13 in #331 and updating the dependency tree across the board.
pip-with-requires-pythonis no longer being installed (#332). Some related bumps were contributed by @woodruffw💰 (#359) and @kurtmckee💰 sent a contributor-facing PR, bumping the linting configuration via #335.💪 New Contributors
🪞 Full Diff: https://github.com/pypa/gh-action-pypi-publish/compare/v1.12.4...v1.13.0
🧔♂️ Release Manager: @webknjaz 🇺🇦
💬 Discuss on Bluesky 🦋, on Mastodon 🐘 and on GitHub.
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.