Skip to content

gh aw add: Markdown security scanner rejects JavaScript package resources containing HTML templates #65960

Description

@pelikhan

Summary

With gh-aw v0.91.0, gh aw add applies the Markdown security scanner to a JavaScript file declared under resources: in an aw.yml package. Legitimate <form> and <script> markup inside a JavaScript template literal produces [html-abuse] errors and prevents package installation or reapplication.

Reproduction

In a fresh git repository, using gh-aw v0.91.0:

gh aw add githubnext/gh-aw-cao@5592db45cdcaa91e8c6e6ca7daefa43668922539 --force

This fails on .github/workflows/shared/setup-github-apps.mjs. Installing with --no-security-scanner succeeds; reapplying the same immutable package revision with the command above fails again.

Observed output:

Adding 58 workflow(s)...
Adding workflow 6/58: setup-github-apps
Security scan failed for workflow
Security scan found 2 issue(s) in workflow markdown:
.github/workflows/shared/setup-github-apps.mjs:285:1: error: [html-abuse] <script> tag can execute arbitrary JavaScript
.github/workflows/shared/setup-github-apps.mjs:285:1: error: [html-abuse] <form> tag can submit data to external servers
failed to add workflow 'githubnext/gh-aw-cao/.github/workflows/shared/setup-github-apps.mjs@5592db45cdcaa91e8c6e6ca7daefa43668922539'
workflow '.github/workflows/shared/setup-github-apps.mjs' failed security scan: 2 issue(s) detected

Expected behavior

Use file-aware/resource-aware security validation rather than interpreting arbitrary JavaScript source as workflow Markdown. This declared .mjs resource should not be rejected solely for an HTML template used by its GitHub App manifest registration page. Preserve applicable security checks for resources and normal Markdown scanning for workflow/prompt content; this is not a request to disable all resource scanning.

Verified source evidence

Workaround and impact

gh aw add githubnext/gh-aw-cao@5592db45cdcaa91e8c6e6ca7daefa43668922539 --force --no-security-scanner

The package's existing public installer documents and uses this workaround. It disables scanning for the whole package, including actual workflow Markdown, just to install one legitimate JavaScript resource. A regression test covering a declared .mjs resource with an HTML template alongside scanned Markdown content would help keep the fix appropriately scoped.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions