Skip to content

[CI] Consolidate style, Serge review and GPU test bots under @diffusers-bot - #14623

Merged
DN6 merged 5 commits into
mainfrom
diffusers-bot
Sep 16, 2026
Merged

DN6 merged 5 commits into
mainfrom
diffusers-bot

Conversation

@DN6

@DN6 DN6 commented Aug 27, 2026

Copy link
Copy Markdown
Collaborator

What does this PR do?

We have multiple bot commands available, but they all have different invocations. This PR consolidates everything under a @diffusers-bot command

e.g.

@diffusers-bot style
@diffusers-bot review
@diffusers-bot pytest

Fixes # (issue)

Before submitting

  • Did you use an AI agent (Claude Code, Codex, Cursor, etc.) to help with this PR? If so:
    • Did you read the Coding with AI agents guide?
    • Did you run the self-review skill on the diff?
    • Did you share the final self-review notes in the PR description or a comment?
  • Did you read the contributor guideline?
  • Did you read our philosophy doc? (important for complex PRs)
  • Was this discussed/approved via a GitHub issue or the forum? Please add a link to it if that's the case.
  • Did you make sure to update the documentation with your changes? Here are the
    documentation guidelines, and
    here are tips on formatting docstrings.
  • Did you write any new necessary tests?
  • Are you the author (or part of the team) of the model/pipeline (only applicable for model/pipeline related PRs)?

Who can review?

Anyone in the community is free to review the PR once the tests have passed. Feel free to tag
members/contributors who may be interested in your PR.

@DN6
DN6 requested a review from sayakpaul August 27, 2026 10:02
@github-actions github-actions Bot added CI size/L PR with diff > 200 LOC labels Aug 27, 2026

@sayakpaul sayakpaul left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks! Can we keep the logic of the individual jobs in their own files and invoke them from diffusers_bot.yml? Otherwise, it's just one big file to maintain which could be burdensome.

Additionally, could we share the auth step? I don't think it would hurt to unify the permissions across all the three jobs?

Comment thread .github/workflows/diffusers_bot.yml Outdated
Comment on lines +5 to +7
# @diffusers-bot style run `make style && make quality` and push the fixes to the PR branch
# @diffusers-bot review request a Serge AI review (also works from an inline review comment)
# @diffusers-bot pytest <args> run `pytest <args>` on a GPU runner, e.g.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

But the comment is /diffusers-bot though.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Right. We would change to using @ mention for all the bots?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

But the problem there is we could have diffusers-bot as an actual GitHub username and the interference would be messy there. So, maybe it's better to stick to /diffusers-bot.

Comment thread .github/workflows/diffusers_bot.yml Outdated
github.event_name == 'issue_comment' &&
github.event.issue.pull_request &&
github.event.issue.state == 'open' &&
contains(github.event.comment.body, '@diffusers-bot review') &&

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For Serge, we use @askserge, though. I am guessing that should still work?

'. + {installation: {id: $iid}} | .comment.body |= sub("@diffusers-bot review"; "@askserge")' ?

@DN6

DN6 commented Sep 7, 2026

Copy link
Copy Markdown
Collaborator Author

@sayakpaul split out the workflows, they all have bot_ prefixes to denote that they're meant to be invoked via @diffusers-bot

@sayakpaul sayakpaul left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The separation looks really nice, thanks! I think it still makes sense to continue to use /diffusers-bot and not @diffusers-bot, though.

See: https://github.com/huggingface/diffusers/pull/14623/changes#r3962237359

@DN6

DN6 commented Sep 14, 2026

Copy link
Copy Markdown
Collaborator Author

@sayakpaul Updated to use /diffusers-bot

@sayakpaul sayakpaul left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great stuff! Thanks Dhruv.

@DN6
DN6 merged commit 5211641 into main Sep 16, 2026
16 checks passed
@DN6
DN6 deleted the diffusers-bot branch September 16, 2026 08:46
@hf-security-analysis

Copy link
Copy Markdown
Contributor

⚠️ Workflow security review — 11 high, 2 medium, 3 low

Scanned 5 workflow file(s) with zizmor, pinact, OSV/GHSA, Claude, in full, as they stand on the default branch.

.github/workflows/bot_style.yml

  • ⚠️ HIGH unpinned-action — .github/workflows/bot_style.yml:34 (via pinact)
    Action is not pinned to an immutable commit SHA: uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9

    Fix: Replace with uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0

  • ⚠️ HIGH unpinned-action — .github/workflows/bot_style.yml:78 (via pinact)
    Action is not pinned to an immutable commit SHA: uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9

    Fix: Replace with uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0

  • ⚠️ HIGH unpinned-action — .github/workflows/bot_style.yml:96 (via pinact)
    Action is not pinned to an immutable commit SHA: uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9

    Fix: Replace with uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0

  • ⚠️ HIGH unpinned-action — .github/workflows/bot_style.yml:135 (via pinact)
    Action is not pinned to an immutable commit SHA: uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7

    Fix: Replace with uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0

  • ⚠️ HIGH unpinned-action — .github/workflows/bot_style.yml:161 (via pinact)
    Action is not pinned to an immutable commit SHA: uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7

    Fix: Replace with uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1

  • ⚠️ HIGH github-app — .github/workflows/bot_style.yml:177 (via zizmor)
    dangerous use of GitHub App tokens — app token inherits blanket installation permissions

    Fix: dangerous use of GitHub App tokens

  • ⚠️ HIGH unpinned-action — .github/workflows/bot_style.yml:185 (via pinact)
    Action is not pinned to an immutable commit SHA: uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9

    Fix: Replace with uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0

  • ⚠️ HIGH unpinned-action — .github/workflows/bot_style.yml:221 (via pinact)
    Action is not pinned to an immutable commit SHA: uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8

    Fix: Replace with uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1

  • ⚠️ HIGH unpinned-action — .github/workflows/bot_style.yml:228 (via pinact)
    Action is not pinned to an immutable commit SHA: uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9

    Fix: Replace with uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0

  • ⚠️ HIGH unpinned-action — .github/workflows/bot_style.yml:294 (via pinact)
    Action is not pinned to an immutable commit SHA: uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9

    Fix: Replace with uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0

  • 🟡 MEDIUM excessive-permissions — .github/workflows/bot_style.yml:1 (via zizmor)
    overly broad permissions — default permissions used due to no permissions: block

    Fix: Declare an explicit permissions: block with the narrowest scopes the job needs, at job level rather than workflow level.

  • 🟡 MEDIUM ref-version-mismatch — .github/workflows/bot_style.yml:177 (via zizmor)
    action's hash pin has mismatched or missing version comment — tag points to commit d72941d797fd

    Fix: The # vX.Y.Z comment does not match the pinned SHA. Either the comment is stale or the pin was tampered with — re-resolve it.

.github/workflows/diffusers_bot.yml

  • ⚠️ HIGH unpinned-action — .github/workflows/diffusers_bot.yml:49 (via pinact)
    Action is not pinned to an immutable commit SHA: uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8

    Fix: Replace with uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0

  • 🔵 LOW self-repository — .github/workflows/diffusers_bot.yml:91 (via zizmor)
    use GitHub's dedicated self-repository syntax — use '$/...' instead of './...'

    Fix: use GitHub's dedicated self-repository syntax

  • 🔵 LOW self-repository — .github/workflows/diffusers_bot.yml:103 (via zizmor)
    use GitHub's dedicated self-repository syntax — use '$/...' instead of './...'

    Fix: use GitHub's dedicated self-repository syntax

  • 🔵 LOW self-repository — .github/workflows/diffusers_bot.yml:117 (via zizmor)
    use GitHub's dedicated self-repository syntax — use '$/...' instead of './...'

    Fix: use GitHub's dedicated self-repository syntax

🔀 A fix PR is open against this branch: #14788

Pinning and static findings are deterministic. Findings marked (via Claude) are model judgements — check them before acting.

DN6 pushed a commit that referenced this pull request Sep 16, 2026
fix(ci): harden workflow files flagged on #14623

Co-authored-by: hf-security-analysis[bot] <265538906+hf-security-analysis[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CI size/L PR with diff > 200 LOC

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants