Skip to content

fix(ci): harden GitHub Actions workflows (#2826) - #2827

Closed
hf-security-analysis[bot] wants to merge 1 commit into
dependabot/github_actions/actions-d16036c01bfrom
security/workflow-hardening/pr-2826
Closed

hf-security-analysis[bot] wants to merge 1 commit into
dependabot/github_actions/actions-d16036c01bfrom
security/workflow-hardening/pr-2826

Conversation

@hf-security-analysis

@hf-security-analysis hf-security-analysis Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Automated hardening of the workflow files flagged on #2826.

Targets dependabot/github_actions/actions-d16036c01b. Files changed, and what changed them:

  • .github/workflows/trufflehog.yml — action pins

Fixed by this PR:

  • HIGH unpinned-action (pinact) — .github/workflows/trufflehog.yml:20

This does not fix everything. 7 further finding(s) (1 high, 6 medium) need a decision this bot should not make for you. They are in the security channel with their locations — deliberately not repeated here, since this repository may be public and they are not fixed yet.

Permissions

.github/workflows/api_inference_build_documentation.yml

build was left as it is — The job only calls the external reusable workflow huggingface/doc-builder/.github/workflows/build_main_documentation.yml, whose job permissions are not visible in this file (it likely needs only contents: read to check out and pushes docs via the HF token secret, but this cannot be verified here).

.github/workflows/api_inference_build_pr_documentation.yml

build was left as it is — The job only calls the external reusable workflow huggingface/doc-builder/.github/workflows/build_pr_documentation.yml, whose steps are not in this file, so its token needs cannot be read here (likely just contents: read to check out and build docs).

.github/workflows/api_inference_upload_pr_documentation.yml

build was left as it is — The job only calls the external reusable workflow huggingface/doc-builder/.github/workflows/upload_pr_documentation.yml, whose steps are not in this file, so its token needs cannot be verified (likely actions: read to download the build artifact from the triggering run, plus possibly pull-requests or issues access for PR comments, though it is given a separate comment_bot_token).

Anything not listed above keeps the permissions it had. To measure a job this could not read, add GitHubSecurityLab/actions-permissions/monitor to it and run the workflow — it reports the minimum the run actually used.

Pinning changes come from pinact and are mechanical. Any other change was generated by Claude — read it before merging.


Note

Low Risk
Comment-only change on an already SHA-pinned GitHub Action; no runtime or permission changes.

Overview
Updates the Secret Leaks workflow so the TruffleHog step’s inline pin comment documents v3.97.6 instead of main. The action reference is unchanged: it still uses commit 64d939a56362f519781c53ea09b27f8d1dc0140a.

This is part of CI workflow hardening (pinact) so pinned third-party actions are labeled with a release version rather than a floating branch name.

Reviewed by Cursor Bugbot for commit 7b4c0d5. Bugbot is set up for automated code reviews on this repo. Configure here.

@dependabot
dependabot Bot deleted the branch dependabot/github_actions/actions-d16036c01b October 6, 2026 09:37
@dependabot dependabot Bot closed this Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants