Skip to content

fix(ci): harden GitHub Actions workflows (#14789) - #14954

Closed
hf-security-analysis[bot] wants to merge 0 commit into
dependabot/github_actions/actions-ca6b5df6adfrom
security/workflow-hardening/pr-14789
Closed

hf-security-analysis[bot] wants to merge 0 commit into
dependabot/github_actions/actions-ca6b5df6adfrom
security/workflow-hardening/pr-14789

Conversation

@hf-security-analysis

@hf-security-analysis hf-security-analysis Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Automated hardening of the workflow files flagged on #14789.

Targets dependabot/github_actions/actions-ca6b5df6ad. Files changed, and what changed them:

  • .github/workflows/claude_review.yml — action pins
  • .github/workflows/pypi_publish.yaml — action pins
  • .github/workflows/trufflehog.yml — action pins

Fixed by this PR:

  • HIGH unpinned-action (pinact) — .github/workflows/claude_review.yml:39
  • HIGH unpinned-action (pinact) — .github/workflows/pypi_publish.yaml:77
  • HIGH unpinned-action (pinact) — .github/workflows/trufflehog.yml:20

This does not fix everything. 44 further finding(s) (40 high, 4 medium) need a decision this bot should not make for you. They are in the security channel with their locations — deliberately not repeated here, since this repository may be public and they are not fixed yet.

Permissions

.github/workflows/bot_pytest.yml

job granted why
gate pull-requests: write The gh api calls use literal paths that add a reaction to the triggering comment (issues/comments/{id}/reactions) and post a comment on the PR (issues/{PR}/comments); on a pull request, pull-requests: write covers both.
gpu contents: read actions/checkout of the PR head ref needs contents: read; the remaining steps install packages and run pytest, and upload-artifact stores to the same run, so none of them use the token.
report pull-requests: write The gh api -X PATCH call to the literal path issues/comments/{CID} edits the bot's comment on the PR, which needs pull-requests: write.

.github/workflows/codeql.yml

codeql was left as it is — Job only calls the external reusable workflow huggingface/security-workflows/.github/workflows/codeql-reusable.yml, whose steps are not in this file; the declared set (security-events: write for SARIF upload, actions/contents/packages: read) is plausible for CodeQL but cannot be verified here.

.github/workflows/pr_link_issue_reminder.yml

job granted why
remind contents: read, issues: write, pull-requests: write The external script utils/remind_link_issue.py is not visible here; going by the job's description, it comments on and closes PRs via PyGithub, which needs pull-requests: write, and issues: write because PR comments go through the issues API. actions/checkout needs contents: read. Verify the script does nothing beyond this, since this set matches the job's existing declaration.

.github/workflows/stale.yml

job granted why
close_stale_issues contents: read, issues: write, pull-requests: write The 'Close stale issues' step runs utils/stale.py with PyGithub, and its contents are not in this file; the stale-bot purpose and the job's existing block point to commenting on and closing issues and PRs (issues: write, pull-requests: write), so check that script to confirm. actions/checkout adds contents: read.

Anything not listed above keeps the permissions it had. To measure a job this could not read, add GitHubSecurityLab/actions-permissions/monitor to it and run the workflow — it reports the minimum the run actually used.

Pinning changes come from pinact and are mechanical. Any other change was generated by Claude — read it before merging.

@github-actions github-actions Bot added CI size/S PR with diff < 50 LOC labels Oct 6, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-ca6b5df6ad branch from 91e74c1 to 34b0044 Compare October 9, 2026 05:25
@hf-security-analysis
hf-security-analysis Bot force-pushed the security/workflow-hardening/pr-14789 branch from fc9aed4 to 34b0044 Compare October 9, 2026 05:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CI size/S PR with diff < 50 LOC

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants