Skip to content

[Safe Outputs Conformance] SEC-004: body fields without sanitization in 2 handlers #50506

Description

@github-actions

Conformance Check Failure

Check ID: SEC-004
Severity: MEDIUM
Category: Security

Problem Description

The conformance checker flags two safe-output handlers that contain a body field with no detectable sanitization call (sanitize, stripHTML, escapeMarkdown, or cleanContent). Per the Safe Outputs Specification, any handler that writes untrusted or externally-influenced content into a GitHub-facing body field MUST sanitize that content before the API call.

Affected Components

  • actions/setup/js/exchange_otlp_workload_identity.cjs — likely a false positive: its two body: occurrences (lines 26, 53) are HTTP request payloads (URLSearchParams / JSON.stringify) sent to a workload-identity token exchange endpoint, not GitHub issue/comment/PR content. This is the same shape of false positive already resolved in actions/setup/js/artifact_client.cjs via a @safe-outputs-exempt SEC-004 annotation.
  • actions/setup/js/report_failed_jobs.cjs — genuine case: issueBody (line 181) is built from a template (failed_jobs_issue.md) interpolated with workflow_name, workflow_source_url, run_url, and a list of failed job names/URLs (formatFailedJobsList). Job names/URLs originate from github.rest.actions.listJobsForWorkflowRun, which for workflows triggered by external/fork PRs could reflect job names defined in a modified workflow file. There is no explicit sanitization call before this content is passed to github.rest.issues.create.
🔍 Current vs Expected Behavior

Current Behavior

  • exchange_otlp_workload_identity.cjs has no @safe-outputs-exempt SEC-004 annotation, so the checker cannot distinguish its transport-layer body from a GitHub content body.
  • report_failed_jobs.cjs interpolates job names/URLs and workflow metadata directly into the issue body string via generateFooterWithExpiration without calling a sanitize/escape helper.

Expected Behavior

Per spec (docs/src/content/docs/specs/safe-outputs-specification.md, SEC-004): handlers that construct GitHub-facing body content from any externally-influenced value must either (a) sanitize the content, or (b) carry a documented @safe-outputs-exempt SEC-004 annotation explaining why sanitization does not apply (as done in artifact_client.cjs, allowed_issue_fields.cjs, assign_agent_helpers.cjs, disable_agentic_workflow.cjs).

Remediation Steps

This task can be assigned to a Copilot coding agent with the following steps:

  1. In actions/setup/js/exchange_otlp_workload_identity.cjs, add a @safe-outputs-exempt SEC-004 comment near the top of the file (matching the style used in artifact_client.cjs) clarifying that the body: fields are outbound HTTP transport payloads for OAuth/token-exchange calls, not GitHub content.
  2. In actions/setup/js/report_failed_jobs.cjs, review whether formatFailedJobsList/template interpolation needs an explicit sanitize/escape call on job names and URLs before they reach issueBody. If job names can only originate from the repository's own trusted workflow definitions (not fork PR content), instead add a @safe-outputs-exempt SEC-004 annotation explaining that trust boundary explicitly.
  3. Re-run the conformance checker to confirm SEC-004 passes cleanly for both files.

Verification

After remediation, verify the fix by running:

bash scripts/check-safe-outputs-conformance.sh

The check SEC-004 should pass without errors.

References

  • Safe Outputs Specification: docs/src/content/docs/specs/safe-outputs-specification.md
  • Conformance Checker: scripts/check-safe-outputs-conformance.sh
  • Run ID: 30981409805
  • Date: 2026-08-05

Generated by ✅ Daily Safe Outputs Conformance Checker · agent · 39.7 AIC · ⌖ 13.7 AIC · ⊞ 6.8K · ◷

  • expires on Aug 5, 2026, 10:32 PM UTC-08:00

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions