Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
35 changes: 35 additions & 0 deletions .github/workflows/build-android-target.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
# This workflow is intended to be run when we need to build the Android SDK and produce artifacts that require secrets
# when the PR source branch does not have access to secrets (e.g. a fork).
# This workflow will run in the context of the target of the PR and have access to secrets.
# This should only be done after reviewing the PR to ensure that no malicious code has been introduced,
# as it could allow the code on the forked branch to have access to workflow secrets.

name: Build Android on PR Target

on:
pull_request_target:
types: [opened, synchronize, reopened]
branches:
- main
Comment on lines +10 to +13

@aikido-pr-checks aikido-pr-checks Bot Aug 14, 2026

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Using unsafe GitHub Actions trigger may allow privilege escalation via CI/CD - critical severity
Using pull_request_target or workflow_run as a trigger is not recommended, as it may allow an attacker to elevate its privileges via the CI/CD pipeline by exfiltrating secrets (e.g. by reading out the caches of the GitHub Actions pipeline or listing loaded secrets in the environment). If the affected repository is open source, the attacker doesn't have to be an insider but could be any GitHub user.

Show fix
Suggested change
pull_request_target:
types: [opened, synchronize, reopened]
branches:
- main
pull_request:
types: [opened, synchronize, reopened]
branches:
- main

Reply @AikidoSec ignore: [REASON] to ignore this issue.
More info


defaults:
run:
shell: bash

jobs:
check-run:
name: Check PR run
uses: bitwarden/gh-actions/.github/workflows/check-run.yml@main
permissions:
contents: read

run-workflow:
name: Build Android
needs: check-run
if: ${{ github.event.pull_request.head.repo.full_name != github.repository }}
uses: ./.github/workflows/build-android.yml
secrets: inherit
permissions:
contents: read
pull-requests: write
id-token: write
8 changes: 8 additions & 0 deletions .github/workflows/build-android.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,14 @@ on:
description: "Update Android Repo - Opens a PR updating the SDK in bitwarden/android"
type: boolean
default: false
workflow_call:
secrets:
AZURE_SUBSCRIPTION_ID:
required: true
AZURE_TENANT_ID:
required: true
AZURE_CLIENT_ID:
required: true

defaults:
run:
Expand Down
35 changes: 35 additions & 0 deletions .github/workflows/build-wasm-internal-target.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
# This workflow is intended to be run when we need to build the WASM SDK and produce artifacts that require secrets
# when the PR source branch does not have access to secrets (e.g. a fork).
# This workflow will run in the context of the target of the PR and have access to secrets.
# This should only be done after reviewing the PR to ensure that no malicious code has been introduced,
# as it could allow the code on the forked branch to have access to workflow secrets.

name: Build @bitwarden/sdk-internal on PR Target

on:
pull_request_target:
types: [opened, synchronize, reopened]
branches:
- main
Comment on lines +10 to +13

@aikido-pr-checks aikido-pr-checks Bot Aug 14, 2026

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Using unsafe GitHub Actions trigger may allow privilege escalation via CI/CD - critical severity
Using pull_request_target or workflow_run as a trigger is not recommended, as it may allow an attacker to elevate its privileges via the CI/CD pipeline by exfiltrating secrets (e.g. by reading out the caches of the GitHub Actions pipeline or listing loaded secrets in the environment). If the affected repository is open source, the attacker doesn't have to be an insider but could be any GitHub user.

Show fix
Suggested change
pull_request_target:
types: [opened, synchronize, reopened]
branches:
- main
pull_request:
types: [opened, synchronize, reopened]
branches:
- main

Reply @AikidoSec ignore: [REASON] to ignore this issue.
More info


defaults:
run:
shell: bash

jobs:
check-run:
name: Check PR run
uses: bitwarden/gh-actions/.github/workflows/check-run.yml@main
permissions:
contents: read

run-workflow:
name: Build @bitwarden/sdk-internal
needs: check-run
if: ${{ github.event.pull_request.head.repo.full_name != github.repository }}
uses: ./.github/workflows/build-wasm-internal.yml
secrets: inherit
permissions:
contents: read
pull-requests: write
id-token: write
8 changes: 8 additions & 0 deletions .github/workflows/build-wasm-internal.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,14 @@ on:
- "rc"
- "hotfix-rc"
workflow_dispatch:
workflow_call:
secrets:
AZURE_SUBSCRIPTION_ID:
required: true
AZURE_TENANT_ID:
required: true
AZURE_CLIENT_ID:
required: true

permissions: {}

Expand Down
34 changes: 34 additions & 0 deletions .github/workflows/enforce-labels-target.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
# This workflow is intended to be run when we need to enforce PR labels
# when the PR source branch does not have access to secrets (e.g. a fork).
# This workflow will run in the context of the target of the PR and have access to secrets.
# This should only be done after reviewing the PR to ensure that no malicious code has been introduced,
# as it could allow the code on the forked branch to have access to workflow secrets.

name: Enforce PR labels on PR Target

on:
pull_request_target:
types: [labeled, unlabeled, opened, edited, synchronize]
branches:
- main

defaults:
run:
shell: bash

jobs:
check-run:
name: Check PR run
uses: bitwarden/gh-actions/.github/workflows/check-run.yml@main
permissions:
contents: read

run-workflow:
name: Enforce Labels
needs: check-run
if: ${{ github.event.pull_request.head.repo.full_name != github.repository }}
uses: ./.github/workflows/enforce-labels.yml
secrets: inherit
permissions:
contents: read
pull-requests: read
Loading