FixVibe

high

Compromised GitHub Action codfish/semantic-release-action Steals CI/CD Secrets

Compromised codfish/semantic-release-action refs can put release workflows and CI/CD secrets at risk. FixVibe GitHub repo scans flag workflow YAML that references the affected refs.

CWE-506

Public incident reports describe a June 2026 compromise of codfish/semantic-release-action, a GitHub Action used for release automation [S1][S2]. Affected Action refs could execute untrusted code inside CI/CD jobs, where release tokens, package-registry credentials, cloud deploy credentials, signing material, or GitHub workflow tokens may be available [S1][S2].

The risk for a specific repository depends on whether its workflow referenced an affected Action ref, whether a job ran after the compromise, and what credentials or permissions that job had. A workflow reference is therefore evidence that deserves immediate cleanup and incident-response review, not proof by itself that credentials were stolen.

Covered by FixVibe

FixVibe's GitHub repo scans flag workflow YAML that references codfish/semantic-release-action refs associated with the June 2026 compromise, showing the workflow file, line and Action reference. If affected workflows did run, rotate long-lived secrets available to those jobs and audit releases, packages, commits, and workflow edits.

Remediation

To reduce risk from this incident:

  • Remove codfish/semantic-release-action from affected workflows or replace the release path with trusted automation [S1][S2].
  • Review GitHub Actions runs after the compromise window for workflows that used the affected Action reference [S2].
  • Rotate long-lived secrets exposed to affected jobs, including package-registry, deploy, cloud, signing, and personal-access tokens where applicable [S1][S2].
  • Pin remaining third-party Actions to reviewed commit SHAs, narrow workflow permissions, and keep release secrets scoped to the minimum jobs that need them.
  • Rerun the FixVibe GitHub repo scan to confirm the compromised Action reference is gone.