Lune

S&P2026顶会

COSSETER: GitHub Actions Permission Reduction Using Demand-Driven Static Analysis

Greg Tystahl, Jonah Ghebremichael, Siddharth Muralee, Sourag Cherupattamoolayil, Antonio Bianchi, Aravind Machiry, Alexandros Kapravelos, William Enck

2026年份
3被引次数

摘要

Security vulnerabilities in GitHub Actions are increasingly leading to software supply chain attacks. In some instances, attackers have modified a project's source code by crafting a malicious issue title. To mitigate such threats, GitHub introduced a permission system that allows project maintainers to customize the privilege granted to workflows and their jobs. Unfortunately, permission policy specification is a known hard problem across nearly all domains of computing, particularly when it is introduced after an ecosystem has been established. This paper proposes Cosseter, a static analysis tool designed to determine least-privilege permission policies for jobs within GitHub Actions workflow specifications. To achieve this goal, Cosseter overcomes state explosion challenges in static analysis of JavaScript Actions that result from packing and nuances in commonly used npm dependencies. We evaluated Cosseter using a dataset of manual permission annotations of JavaScript Actions used by industry tools and found that it has a comparable precision and recall. We further evaluate Cosseter at scale, studying the permission needs of 1,842 vulnerable workflows identified by prior work and extracting permission summaries for 8,353\mathbf{8, 3 5 3} JavaScript Actions. We find that Cosseter's permission policy can reduce 76 % of 1,274 high severity code injection vulnerabilities into medium, low, or no severity. In doing so, we demonstrate how Cosseter suggested permissions can provide a valuable defense against software supply chain attacks.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖