Skip to content

fix(ci): harden GitHub Actions workflows (#14623) - #14788

Merged
DN6 merged 1 commit into
mainfrom
security/workflow-hardening/pr-14623
Sep 16, 2026
Merged

DN6 merged 1 commit into
mainfrom
security/workflow-hardening/pr-14623

Conversation

@hf-security-analysis

@hf-security-analysis hf-security-analysis Bot commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

Automated hardening of the workflow files flagged on #14623.

Targets main. Files changed:

  • .github/workflows/bot_style.yml
  • .github/workflows/diffusers_bot.yml

Fixed by this PR:

  • HIGH unpinned-action (pinact) — .github/workflows/bot_style.yml:34
  • HIGH unpinned-action (pinact) — .github/workflows/bot_style.yml:78
  • HIGH unpinned-action (pinact) — .github/workflows/bot_style.yml:96
  • HIGH unpinned-action (pinact) — .github/workflows/bot_style.yml:135
  • HIGH unpinned-action (pinact) — .github/workflows/bot_style.yml:161
  • HIGH github-app (zizmor) — .github/workflows/bot_style.yml:177
  • HIGH unpinned-action (pinact) — .github/workflows/bot_style.yml:185
  • HIGH unpinned-action (pinact) — .github/workflows/bot_style.yml:221
  • HIGH unpinned-action (pinact) — .github/workflows/bot_style.yml:228
  • HIGH unpinned-action (pinact) — .github/workflows/bot_style.yml:294
  • HIGH unpinned-action (pinact) — .github/workflows/diffusers_bot.yml:49

Reported on the pull request but not fixed here — each needs a decision this bot should not make for you:

  • MEDIUM excessive-permissions (zizmor) — .github/workflows/bot_style.yml:1

Permissions

.github/workflows/bot_style.yml

job granted why
run contents: read, pull-requests: read The github-script steps only call pulls.get and a GraphQL commit query (pull-requests: read, contents: read for the commit object), and actions/checkout of the fork plus same-run upload-artifact need no more than contents: read.
push contents: read, issues: write, pull-requests: read The 'Comment on PR with workflow run link' and 'Comment on PR' steps use issues.createComment/updateComment on the PR (issues: write), the re-validation step reads pulls.get (pull-requests: read), and checkout needs contents: read; the actual push uses the separate GitHub App token, not GITHUB_TOKEN, so contents: write is not required here.

Anything not listed above keeps the permissions it had. To measure a job this could not read, add GitHubSecurityLab/actions-permissions/monitor to it and run the workflow — it reports the minimum the run actually used.

Pinning changes come from pinact and are mechanical. Any other change was generated by Claude — read it before merging.

Closes huggingface/tracking-issues#946

@DN6
DN6 merged commit ae2e4c7 into main Sep 16, 2026
16 checks passed
@DN6
DN6 deleted the security/workflow-hardening/pr-14623 branch September 16, 2026 15:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CI size/S PR with diff < 50 LOC

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant