COSSETER: GitHub Actions Permission Reduction Using Demand-Driven Static Analysis
Greg Tystahl, Jonah Ghebremichael, Siddharth Muralee, Sourag Cherupattamoolayil, Antonio Bianchi, Aravind Machiry, Alexandros Kapravelos, William Enck
Abstract
Security vulnerabilities in GitHub Actions are increasingly leading to software supply chain attacks. In some instances, attackers have modified a project's source code by crafting a malicious issue title. To mitigate such threats, GitHub introduced a permission system that allows project maintainers to customize the privilege granted to workflows and their jobs. Unfortunately, permission policy specification is a known hard problem across nearly all domains of computing, particularly when it is introduced after an ecosystem has been established. This paper proposes Cosseter, a static analysis tool designed to determine least-privilege permission policies for jobs within GitHub Actions workflow specifications. To achieve this goal, Cosseter overcomes state explosion challenges in static analysis of JavaScript Actions that result from packing and nuances in commonly used npm dependencies. We evaluated Cosseter using a dataset of manual permission annotations of JavaScript Actions used by industry tools and found that it has a comparable precision and recall. We further evaluate Cosseter at scale, studying the permission needs of 1,842 vulnerable workflows identified by prior work and extracting permission summaries for JavaScript Actions. We find that Cosseter's permission policy can reduce 76 % of 1,274 high severity code injection vulnerabilities into medium, low, or no severity. In doing so, we demonstrate how Cosseter suggested permissions can provide a valuable defense against software supply chain attacks.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- Characterizing the Security of Github CI WorkflowsIgibek Koishybayev, Aleksandr Nahapetyan, Raima Zachariah, Siddharth Muralee et al.USENIX Security 2022
- ARGUS: A Framework for Staged Static Taint Analysis of GitHub Workflows and ActionsSiddharth Muralee, Igibek Koishybayev, Aleksandr Nahapetyan, Greg Tystahl et al.USENIX Security 2023
- Action Required: A Mixed-Methods Study of Security Practices in GitHub ActionsYusuke Kubo, Fumihiro Kanei, Mitsuaki Akiyama, Takuro Wakai et al.NDSS 2026 · 3 citations
- Continuous Intrusion: Characterizing the Security of Continuous Integration ServicesYacong Gu, Lingyun Ying, Huajun Chai, Chu Qiao et al.S&P 2023
- A Mixed-Methods Study of Open-Source Software Maintainers On Vulnerability Management and Platform Security FeaturesJessy Ayala, Yu-Jye Tung, Joshua GarciaUSENIX Security 2025
