Skip to content

[uk-ai-resilience] Untracked unpinned pip install of geo-optimizer-skill in daily-geo-optimizer (alert #768, Tier C) #61379

Description

@github-actions

Summary

CodeQL alert #768 (pr-action.rules.github-actions.pip-install.actions-pip-install-inline-no-hash-check, severity: error) flags .github/workflows/daily-geo-optimizer.lock.yml:2096 (compiled output of source .github/workflows/daily-geo-optimizer.md:53):

- name: Install geo-optimizer-skill
  run: pip install geo-optimizer-skill

This installs a third-party PyPI package with no version pin and no hash check, executed in a daily scheduled CI job. This alert was surfaced by PR #61359 ("Fix stale docker action pins in wasm golden fixture", merged 2026-09-16), which touched this workflow area while re-pinning stale Docker action SHAs. It has no matching open tracking issue, breaking the classification → control-verification loop for this run's recent-changes scope (7-day lookback since 2026-09-09T15:31:12Z).

Tier & risk-scoring

  • Tier: C — Restricted Pending Review
  • Exposure amplification: Medium–High — an unpinned pip install of a third-party package in a recurring scheduled workflow means any future malicious or compromised release of geo-optimizer-skill (https://github.com/Auriti-Labs/geo-optimizer-skill) would be pulled in automatically on the next run, with no version gate.
  • Patchability: High — pin to an exact version (pip install geo-optimizer-skill==<version>) and/or add hash verification (--require-hashes with a requirements.txt).
  • Detectability: Low — a supply-chain compromise here would be silent; no current alerting on unexpected package behavior changes.
  • Operational fragility: High.
  • Ownership confidence: Medium — the workflow is owned by this repo, but the third-party package release cadence/security posture is external and not verified here.

Remediation action

  • Pin geo-optimizer-skill to an exact, reviewed version in .github/workflows/daily-geo-optimizer.md (source), then run make recompile to regenerate daily-geo-optimizer.lock.yml.
  • Where feasible, add hash verification (--require-hashes with a pinned requirements.txt) or vendor a reviewed copy.
  • SLA urgency: Critical (unpinned third-party code execution in a scheduled CI job).

Reference

Full governance analysis: see the linked discussion report #aw_ukgov0916.

Generated by UK AI Operational Resilience · copilot · auto · 94.4 AIC · ⌖ 7.9 AIC · ⊞ 8.2K · ◷

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions