{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T06:59:52Z","timestamp":1782975592091,"version":"3.54.5"},"reference-count":66,"publisher":"IEEE","license":[{"start":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T00:00:00Z","timestamp":1779062400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T00:00:00Z","timestamp":1779062400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-2207008,CNS2247686,CNS-2247688"],"award-info":[{"award-number":["CNS-2207008,CNS2247686,CNS-2247688"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026,5,18]]},"DOI":"10.1109\/sp63933.2026.00067","type":"proceedings-article","created":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T19:34:20Z","timestamp":1782934460000},"page":"2628-2645","source":"Crossref","is-referenced-by-count":0,"title":["COSSETER: GitHub Actions Permission Reduction Using Demand-Driven Static Analysis"],"prefix":"10.1109","author":[{"given":"Greg","family":"Tystahl","sequence":"first","affiliation":[{"name":"North Carolina State University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jonah","family":"Ghebremichael","sequence":"additional","affiliation":[{"name":"North Carolina State University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Siddharth","family":"Muralee","sequence":"additional","affiliation":[{"name":"Purdue University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sourag","family":"Cherupattamoolayil","sequence":"additional","affiliation":[{"name":"Purdue University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Antonio","family":"Bianchi","sequence":"additional","affiliation":[{"name":"Purdue University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Aravind","family":"Machiry","sequence":"additional","affiliation":[{"name":"Purdue University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Alexandros","family":"Kapravelos","sequence":"additional","affiliation":[{"name":"North Carolina State University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"William","family":"Enck","sequence":"additional","affiliation":[{"name":"North Carolina State University"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","article-title":"Continuous delivery: reliable software releases through build, test, and deployment automation","author":"Humble","year":"2010","journal-title":"Pearson Education"},{"key":"ref2","volume-title":"Travis CI - Test and Deploy Your Code with Confidence"},{"key":"ref3","volume-title":"Continuous Integration and Delivery - CircleCI"},{"key":"ref4","volume-title":"Set up Automated CI Systems with GitLab"},{"key":"ref5","volume-title":"Github Actions"},{"key":"ref6","volume-title":"How We Discovered Vulnerabilities in CI\/CD Pipelines of Popular Open-Source Projects","author":"Ilgayev","year":"2022"},{"key":"ref7","volume-title":"Vulnerable GitHub Actions Workflows Part 1: Privilege Escalation Inside Your CI\/CD Pipeline"},{"key":"ref8","article-title":"ARGUS: A Framework for Staged Static Taint Analysis of GitHub Workflows and Actions","volume-title":"Proceedings of the USENIX Security Symposium","author":"Muralee","year":"2023"},{"key":"ref9","volume-title":"Exploiting GitHub Actions on open source projects","year":"2022"},{"key":"ref10","volume-title":"Github actions updating the default github_token permissions to readonly"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046779"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382222"},{"key":"ref13","article-title":"On demystifying the android application framework: Re-visiting android permission specification analysis","volume-title":"Proceedings of the USENIX Security Symposium","author":"Backes","year":"2016"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.1996.502675"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.2001.924296"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/582419.582452"},{"key":"ref17","volume-title":"GitHub token permissions Monitor and Advisor actions"},{"key":"ref18","article-title":"Mining Node.js Vulnerabilities via Object Dependence Graph and Query","volume-title":"Proceedings of the USENIX Security Symposium","author":"Li"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179352"},{"key":"ref20","volume-title":"Cosseter source code archive","author":"Tystahl","year":"2025"},{"key":"ref21","volume-title":"About custom actions"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/3560835.3564554"},{"key":"ref23","volume-title":"Set up your GitHub Actions workflow with a specific version of node.js"},{"key":"ref24","volume-title":"Checkout actions"},{"key":"ref25","volume-title":"GitHub Action to publish artifacts to GitHub Pages for deployments"},{"key":"ref26","volume-title":"Semgrep OSS is a fast, open-source, static analysis tool for searching code, finding bugs, and enforcing code standards at editor, commit, and CI time"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/24039.24041"},{"key":"ref28","volume-title":"ncc simple cli for compiling a node.js module int oa single file, together with all its dependencies, gcc-style"},{"key":"ref29","volume-title":"Create a javascript action"},{"key":"ref30","volume-title":"Step Security Homepage"},{"key":"ref31","volume-title":"StepSecurity knowledge base"},{"key":"ref32","volume-title":"Permission comparison for cosseter, step security, and github dynamic","author":"Tystahl","year":"2025"},{"key":"ref33","article-title":"The Effectiveness of Application Permissions","volume-title":"Proceedings of the USENIX Conference on Web Application Development (WebApps)","author":"Felt","year":"2011"},{"key":"ref34","article-title":"Permission Re-Delegation: Attacks and Defenses","volume-title":"Proceedings of the USENIX Security Symposium","author":"Felt","year":"2011"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1145\/3355369.3355584"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/2046614.2046626"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/Trustcom\/BigDataSE\/ICESS.2017.303"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2014.2322867"},{"key":"ref39","author":"Amusuo","year":"2024","journal-title":"Ztd_JAVA: Mitigating software supply chain vulnerabilities via zero-trust dependencies"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2007.39"},{"key":"ref41","article-title":"Linux capabilities: making them work","volume-title":"Linux symposium","volume":"8","author":"Hallyn","year":"2008"},{"key":"ref42","volume-title":"Linux Capabilities and Seccomp"},{"key":"ref43","article-title":"Mir: Automated Quantifiable Privilege Reduction Against Dynamic Library Compromise in JavaScript","author":"Vasilakis","year":"2020","journal-title":"arXiv preprint"},{"key":"ref44","article-title":"Characterizing the Security of Github CI Workflows","volume-title":"Proceedings of the USENIX Security Symposium","author":"Koishybayev"},{"key":"ref45","volume-title":"CodeQL Queries From GitHub"},{"key":"ref46","volume-title":"Raven - CI\/CD Security Analyzer"},{"key":"ref47","volume-title":"poutine - security scanner"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1145\/3664476.3664497"},{"key":"ref49","volume-title":"Harden-Runner by StepSecuity"},{"key":"ref50","volume-title":"Bolt Action"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.4236\/jsea.2024.175018"},{"key":"ref52","volume-title":"cimon action"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/MSR.2019.00029"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/BCD2018.2018.00017"},{"key":"ref55","article-title":"Freezing the Web: A Study of ReDoS Vulnerabilities in JavaScript-based Web Servers","volume-title":"Proceedings of the USENIX Security Symposium","author":"Staicu"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2018.2845851"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1145\/2001420.2001442"},{"key":"ref58","doi-asserted-by":"crossref","DOI":"10.1145\/3643991.3644899","article-title":"Quantifying Security Issues in Reusable JavaScript Actions in GitHub Workflows","volume-title":"Proceedings of the International Conference on Mining Software Repositories (MSR)","author":"Onsori Delicheh","year":"2024"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1145\/2635868.2635904"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1145\/2491411.2491417"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1145\/2814270.2814272"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1145\/1809028.1806598"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1145\/2491411.2491447"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2015.51"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1145\/3106741"},{"key":"ref66","volume-title":"Expressions and Operations"}],"event":{"name":"2026 IEEE Symposium on Security and Privacy (SP)","location":"San Francisco, CA, USA","start":{"date-parts":[[2026,5,18]]},"end":{"date-parts":[[2026,5,21]]}},"container-title":["2026 IEEE Symposium on Security and Privacy (SP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11573355\/11573356\/11573435.pdf?arnumber=11573435","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T05:27:14Z","timestamp":1782970034000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11573435\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,18]]},"references-count":66,"URL":"https:\/\/doi.org\/10.1109\/sp63933.2026.00067","relation":{},"subject":[],"published":{"date-parts":[[2026,5,18]]}}}