https://github.com/CycodeLabs/raven Skip to content Toggle navigation Sign up * Product + Actions Automate any workflow + Packages Host and manage packages + Security Find and fix vulnerabilities + Codespaces Instant dev environments + Copilot Write better code with AI + Code review Manage code changes + Issues Plan and track work + Discussions Collaborate outside of code Explore + All features + Documentation + GitHub Skills + Blog * Solutions For + Enterprise + Teams + Startups + Education By Solution + CI/CD & Automation + DevOps + DevSecOps Resources + Learning Pathways + White papers, Ebooks, Webinars + Customer Stories + Partners * Open Source + GitHub Sponsors Fund open source developers + The ReadME Project GitHub community articles Repositories + Topics + Trending + Collections * Pricing Search or jump to... Search code, repositories, users, issues, pull requests... Search [ ] Clear Search syntax tips Provide feedback We read every piece of feedback, and take your input very seriously. [ ] [ ] Include my email address so I can be contacted Cancel Submit feedback Saved searches Use saved searches to filter your results more quickly Name [ ] Query [ ] To see all available qualifiers, see our documentation. Cancel Create saved search Sign in Sign up You signed in with another tab or window. Reload to refresh your session. You signed out in another tab or window. Reload to refresh your session. You switched accounts on another tab or window. Reload to refresh your session. Dismiss alert {{ message }} CycodeLabs / raven Public * Notifications * Fork 11 * Star 198 RAVEN (Risk Analysis and Vulnerability Enumeration for CI/CD) License Apache-2.0 license 198 stars 11 forks Activity Star Notifications * Code * Issues 18 * Pull requests 2 * Actions * Projects 0 * Security * Insights More * Code * Issues * Pull requests * Actions * Projects * Security * Insights CycodeLabs/raven This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository. main Switch branches/tags [ ] Branches Tags Could not load branches Nothing to show {{ refName }} default View all branches Could not load tags Nothing to show {{ refName }} default View all tags Name already in use A tag already exists with the provided branch name. Many Git commands accept both tag and branch names, so creating this branch may cause unexpected behavior. Are you sure you want to create this branch? Cancel Create 3 branches 4 tags Code * Local * Codespaces * Clone HTTPS GitHub CLI [https://github.com/C] Use Git or checkout with SVN using the web URL. [gh repo clone Cycode] Work fast with our official CLI. Learn more about the CLI. * Open with GitHub Desktop * Download ZIP Sign In Required Please sign in to use Codespaces. Launching GitHub Desktop If nothing happens, download GitHub Desktop and try again. Launching GitHub Desktop If nothing happens, download GitHub Desktop and try again. Launching Xcode If nothing happens, download Xcode and try again. Launching Visual Studio Code Your codespace will open once ready. There was a problem preparing your codespace, please try again. Latest commit @elad-pticha elad-pticha Issue template (#113) ... fe70b2a Oct 31, 2023 Issue template (#113) fe70b2a Git stats * 52 commits Files Permalink Failed to load latest commit information. Type Name Latest commit message Commit time .github Issue template (#113) October 31, 2023 11:00 assets/images Update download error logs and Reporter (#94) October 24, 2023 15:12 deployment Improved setup process. (#74) October 8, 2023 17:58 docs [Docs] - Add More Documentation Of Vulnerabilities (#98) October 25, 2023 16:46 library refactor: query library and reporting (#99) October 29, 2023 12:09 src Changed logging msg from python3 main.py -> raven (#107) October 29, 2023 16:44 tests feat: Multiple organization scan and fixed broken py2neo (#83) October 11, 2023 11:48 .gitignore Add Cimon shield (#100) October 26, 2023 12:48 LICENSE.md Renamed LICENSE -> LICENSE.md (#67) October 1, 2023 18:11 MANIFEST.in refactor: Refactor code and deleted deprecated code (#60) October 1, 2023 15:49 Makefile Moved pip install command to Makefile (#88) October 22, 2023 13:45 README.md refactor: query library and reporting (#99) October 29, 2023 12:09 install.sh fix: Fixed install process (#87) October 22, 2023 13:35 main.py refactor: Refactor code and deleted deprecated code (#60) October 1, 2023 15:49 requirements.txt [Cycode] Fix for vulnerable manifest file dependency - urllib3 update... October 22, 2023 14:17 setup.py Improved setup process. (#74) October 8, 2023 17:58 View code [ ] Raven - CI/CD Security Analyzer What is Raven Why Raven Setup && Run Prerequisites Infrastructure Usage Download Download Organization Repositories Download Public Repositories Index Report Examples Rate Limiting Functionalities Downloader Indexer Knowledge Base Current Limitations Future Research Work Contributing License Hall of Fame - Vulnerabilities Found and Disclosed Using Raven README.md Raven - CI/CD Security Analyzer License GitHub release (latest by date) [6874747073] RAVEN (Risk Analysis and Vulnerability Enumeration for CI/CD) is a powerful security tool designed to perform massive scans for GitHub Actions CI workflows and digest the discovered data into a Neo4j database. Raven With Raven, we were able to identify and report security vulnerabilities in some of the most popular repositories hosted on GitHub, including: * FreeCodeCamp (the most popular project on GitHub) * Storybook (One of the most popular frontend frameworks) * Fluent UI by Microsoft * and much more We listed all vulnerabilities discovered using Raven in the tool Hall of Fame. What is Raven The tool provides the following capabilities to scan and analyze potential CI/CD vulnerabilities: * [?] Downloader: You can download workflows and actions necessary for analysis. Workflows can be downloaded for a specified organization or for all repositories, sorted by star count. Performing this step is a prerequisite for analyzing the workflows. * Indexer: Digesting the downloaded data into a graph-based Neo4j database. This process involves establishing relationships between workflows, actions, jobs, steps, etc. * Query Library: We created a library of pre-defined queries based on research conducted by the community. * Report: Raven has a simple way of reporting suspicious findings. As an example, it can be incorporated into the CI process for pull requests and run there. Possible usages for Raven: * Scanner for your own organization's security * Scanning specified organizations for bug bounty purposes * Scan everything and report issues found to save the internet * Research and learning purposes This tool provides a reliable and scalable solution for CI/CD security analysis, enabling users to query bad configurations and gain valuable insights into their codebase's security posture. Why Raven In the past year, Cycode Labs conducted extensive research on fundamental security issues of CI/CD systems. We examined the depths of many systems, thousands of projects, and several configurations. The conclusion is clear - the model in which security is delegated to developers has failed. This has been proven several times in our previous content: * A simple injection scenario exposed dozens of public repositories, including popular open-source projects. * We found that one of the most popular frontend frameworks was vulnerable to the innovative method of branch injection attack. * We detailed a completely different attack vector, 3rd party integration risks, the most popular project on GitHub, and thousands more. * Finally, the Microsoft 365 UI framework, with more than 300 million users, is vulnerable to an additional new threat - an artifact poisoning attack. * Additionally, we found, reported, and disclosed hundreds of other vulnerabilities privately. Each of the vulnerabilities above has unique characteristics, making it nearly impossible for developers to stay up to date with the latest security trends. Unfortunately, each vulnerability shares a commonality - each exploitation can impact millions of victims. It was for these reasons that Raven was created, a framework for CI/ CD security analysis workflows (and GitHub Actions as the first use case). In our focus, we examined complex scenarios where each issue isn't a threat on its own, but when combined, they pose a severe threat. Setup && Run To get started with Raven, follow these installation instructions: Step 1: Download the latest stable version, The install script requires curl, wget and jq curl -sSfL https://raw.githubusercontent.com/CycodeLabs/raven/f020094d175ab5cd0eb10442c6f7728485cc6903/install.sh | bash cd raven or, you can download the latest release from https://github.com/ CycodeLabs/raven/releases/latest Step 2: Create a virtual environment python3 -m venv .venv source .venv/bin/activate Step 3: Build a containerized environment and install Raven sudo make setup Step 4: Run Raven raven Prerequisites * Python 3.9+ * Docker Compose v2.1.0+ * Docker Engine v1.13.0+ Infrastructure Raven is using two primary docker containers: Redis and Neo4j. make setup will run a docker-compose command to prepare that environment. Infrastructure Usage The tool contains two main functionalities, download and index. Download Download Organization Repositories usage: raven download org [-h] --token TOKEN [--debug] [--redis-host REDIS_HOST] [--redis-port REDIS_PORT] [--clean-redis] --org-name ORG_NAME options: -h, --help show this help message and exit --token TOKEN GITHUB_TOKEN to download data from Github API (Needed for effective rate-limiting) --debug Whether to print debug statements, default: False --redis-host REDIS_HOST Redis host, default: localhost --redis-port REDIS_PORT Redis port, default: 6379 --clean-redis, -cr Whether to clean cache in the redis, default: False --org-name ORG_NAME Organization name to download the workflows Download Public Repositories usage: raven download crawl [-h] --token TOKEN [--debug] [--redis-host REDIS_HOST] [--redis-port REDIS_PORT] [--clean-redis] [--max-stars MAX_STARS] [--min-stars MIN_STARS] options: -h, --help show this help message and exit --token TOKEN GITHUB_TOKEN to download data from Github API (Needed for effective rate-limiting) --debug Whether to print debug statements, default: False --redis-host REDIS_HOST Redis host, default: localhost --redis-port REDIS_PORT Redis port, default: 6379 --clean-redis, -cr Whether to clean cache in the redis, default: False --max-stars MAX_STARS Maximum number of stars for a repository --min-stars MIN_STARS Minimum number of stars for a repository, default: 1000 Index usage: raven index [-h] [--redis-host REDIS_HOST] [--redis-port REDIS_PORT] [--clean-redis] [--neo4j-uri NEO4J_URI] [--neo4j-user NEO4J_USER] [--neo4j-pass NEO4J_PASS] [--clean-neo4j] [--debug] options: -h, --help show this help message and exit --redis-host REDIS_HOST Redis host, default: localhost --redis-port REDIS_PORT Redis port, default: 6379 --clean-redis, -cr Whether to clean cache in the redis, default: False --neo4j-uri NEO4J_URI Neo4j URI endpoint, default: neo4j://localhost:7687 --neo4j-user NEO4J_USER Neo4j username, default: neo4j --neo4j-pass NEO4J_PASS Neo4j password, default: 123456789 --clean-neo4j, -cn Whether to clean cache, and index from scratch, default: False --debug Whether to print debug statements, default: False Report usage: raven report [-h] [--redis-host REDIS_HOST] [--redis-port REDIS_PORT] [--clean-redis] [--neo4j-uri NEO4J_URI] [--neo4j-user NEO4J_USER] [--neo4j-pass NEO4J_PASS] [--clean-neo4j] [--tag TAG] [--severity SEVERITY] [--queries-path QUERIES_PATH] {slack} ... positional arguments: {slack} slack Send report to slack channel options: -h, --help show this help message and exit --redis-host REDIS_HOST Redis host, default: localhost --redis-port REDIS_PORT Redis port, default: 6379 --clean-redis, -cr Whether to clean cache in the redis, default: False --neo4j-uri NEO4J_URI Neo4j URI endpoint, default: neo4j://localhost:7687 --neo4j-user NEO4J_USER Neo4j username, default: neo4j --neo4j-pass NEO4J_PASS Neo4j password, default: 123456789 --clean-neo4j, -cn Whether to clean cache, and index from scratch, default: False --tag TAG, -t TAG Filter queries with specific tag --severity SEVERITY, -s SEVERITY Filter queries by severity level (default: info) --queries-path QUERIES_PATH, -dp QUERIES_PATH Queries folder (default: library) Examples Retrieve all workflows and actions associated with the organization. raven download org --token $GITHUB_TOKEN --org-name microsoft --org-name google --debug Scrape all publicly accessible GitHub repositories. raven download crawl --token $GITHUB_TOKEN --min-stars 100 --max-stars 1000 --debug After finishing the download process or if interrupted using Ctrl+C, proceed to index all workflows and actions into the Neo4j database. raven index --debug Now, we can generate a report using our query library. raven report --severity high --tag injection --tag unauthenticated Rate Limiting For effective rate limiting, you should supply a Github token. For authenticated users, the next rate limiting applies: * Code search - 30 queries per minute * Any other API - 5000 per hour Functionalities Downloader * If the workflow contains an action, the downloader will also download it. * If the workflow references a reusable workflow, the downloader will also download it. Indexer * If the indexer finds workflow uses an action, it will create a proper connection to it in the graph * Same applies to reusable workflows * Same applies to workflow triggered through workflow_call Knowledge Base * Issue Injections * Pull Request Injections * Workflow Run Injections * CodeSee Injections Current Limitations * It is possible to run external action by referencing a folder with a Dockerfile (without action.yml). Currently, this behavior isn't supported. * It is possible to run external action by referencing a docker container through the docker://... URL. Currently, this behavior isn't supported. * It is possible to run an action by referencing it locally. This creates complex behavior, as it may come from a different repository that was checked out previously. The current behavior is trying to find it in the existing repository. * We aren't modeling the entire workflow structure. If additional fields are needed, please submit a pull request according to the contribution guidelines. Future Research Work * Implementation of taint analysis. Example use case - a user can pass a pull request title (which is controllable parameter) to an action parameter that is named data. That action parameter may be used in a run command: - run: echo ${{ inputs.data }}, which creates a path for a code execution. * Expand the research for findings of harmful misuse of GITHUB_ENV. This may utilize the previous taint analysis as well. * Research whether actions/github-script has an interesting threat landscape. If it is, it can be modeled in the graph. Contributing We encourage contributions from the community to help improve our tooling and research. We manage contributions primarily through GitHub Issues and Pull Requests. If you have a feature request, bug report, or any improvement suggestions, please create an issue to discuss it. To start contributing, you may check good first issue label to get started quickly into the code base. To contribute code changes, fork our repository, make your modifications, and then submit a pull request. Feel free to reach out to the development team through research@cycode.com. We appreciate your collaboration and look forward to your valuable contributions! License Apache License 2.0 Hall of Fame - Vulnerabilities Found and Disclosed Using Raven Name Stars Fix Additional Sources freeCodeCamp/freeCodeCamp [6874747073] CodeSee package Blog update, 0871341 storybookjs/storybook [6874747073] ffb8558 Blog tiangolo/fastapi [6874747073] 9efab1b LinkedIn withastro/astro [6874747073] 650fb1a Blog statelyai/xstate [6874747073] CodeSee package Blog update docker-slim/docker-slim [6874747073] CodeSee package Blog update microsoft/fluentui [6874747073] 2ea6195 Blog tiangolo/sqlmodel [6874747073] cf36b2d LinkedIn tiangolo/typer [6874747073] 0c106a1 LinkedIn autogluon/autogluon [6874747073] ca18fa9 liquibase/liquibase [6874747073] 3278525 Blog ossf/scorecard [6874747073] c9f582b Ombi-app/Ombi [6874747073] 5cc0d77 Blog wireapp/wire-ios [6874747073] 9d39d6c Blog cloudscape-design/components [6874747073] 2921d2d DynamoDS/Dynamo [6874747073] Disabled Blog workflow fauna/faunadb-js [6874747073] ee6f53f Blog apache/ [6874747073] 53c18e5 Blog incubator-kie-kogito-runtimes Raven About RAVEN (Risk Analysis and Vulnerability Enumeration for CI/CD) Resources Readme License Apache-2.0 license Security policy Security policy Activity Stars 198 stars Watchers 5 watching Forks 11 forks Report repository Releases 4 v1.0.3 Latest Oct 22, 2023 + 3 releases Packages 0 No packages published Contributors 4 * @elad-pticha elad-pticha elad_pt * @oreenlivnicode oreenlivnicode * @alex-ilgayev alex-ilgayev Alex Ilgayev * @cycode-security[bot] cycode-security[bot] Languages * Python 97.4% * Shell 1.5% * Other 1.1% Footer (c) 2023 GitHub, Inc. Footer navigation * Terms * Privacy * Security * Status * Docs * Contact GitHub * Pricing * API * Training * Blog * About You can't perform that action at this time.