FixVibe

// 코드 / 스포트라이트

Compromised codfish GitHub Action

Release workflows should not keep pointing at compromised Action refs.

What it is

CI/CD release workflows are high-value supply-chain targets because they often hold package-registry tokens, cloud deploy credentials, GitHub tokens, and release automation permissions. A compromised third-party Action in that path can put the build environment at risk even when the application source code is otherwise clean.

How it happens

A workflow step that uses a third-party Action runs that Action's code with the secrets and permissions the job holds. Release workflows are the worst place for a compromised one, because they usually carry package-registry, cloud-deploy, and GitHub tokens. The reference in your workflow file is the thing to fix: it keeps pointing the job at the compromised code until it is removed or pinned to a reviewed commit.

What an attacker gets

If an affected workflow ran after the compromise window with release or deploy secrets available, teams should treat those job-scoped credentials as potentially exposed until the run history, logs, release artifacts, and downstream package or deploy activity are reviewed.

// what fixvibe reports

What FixVibe reports

Runs when you connect a GitHub repository, on Pro and above. Each finding shows the file and line, its severity and fix steps you can paste into your AI coding tool.

How to fix it

Remove codfish/semantic-release-action from affected workflows or replace the release path with trusted automation. Review workflow runs after the compromise window, rotate secrets exposed to any affected jobs, rebuild clean CI caches or images where needed, pin remaining third-party Actions to reviewed SHAs, and keep workflow permissions narrowly scoped.

// 내 앱에서 직접 실행해보세요

FixVibe가 지켜보는 동안 계속 배포하세요.

Connect a GitHub repo to check its code, dependencies and workflows.

소스 코드
198
이 카테고리에서 실행되는 테스트
모듈
155
전용 소스 코드 검사
GitHub repos
190+
checks on each connected repo
Connect GitHub →

// 최신 체크 · 실용적인 수정 · 자신 있게 배포

Compromised codfish GitHub Action: what it is and how to fix it · FixVibe