Skip to content

fix(ci): harden GitHub Actions workflows (#115) - #116

Open
hf-security-analysis[bot] wants to merge 1 commit into
dependabot/github_actions/actions-29e98514e7from
security/workflow-hardening/pr-115
Open

hf-security-analysis[bot] wants to merge 1 commit into
dependabot/github_actions/actions-29e98514e7from
security/workflow-hardening/pr-115

Conversation

@hf-security-analysis

@hf-security-analysis hf-security-analysis Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

Automated hardening of the workflow files flagged on #115.

Targets dependabot/github_actions/actions-29e98514e7. Files changed:

  • .github/workflows/upload_pr_documentation.yml

This does not fix everything. 7 further finding(s) (1 high, 6 medium) need a decision this bot should not make for you. They are in the security channel with their locations — deliberately not repeated here, since this repository may be public and they are not fixed yet.

Permissions

.github/workflows/build_documentation.yml

build was left as it is — This job only calls the external reusable workflow huggingface/doc-builder/.github/workflows/build_main_documentation.yml, which is not in this file, so the permissions its jobs require cannot be read here; the hf_token secret is irrelevant to token scopes.

.github/workflows/build_pr_documentation.yml

build was left as it is — This job only calls the external reusable workflow huggingface/doc-builder/.github/workflows/build_pr_documentation.yml, whose job-level permission needs are not visible in this file, so the required scopes cannot be determined here.

.github/workflows/upload_pr_documentation.yml

build was left as it is — This job only delegates to an external reusable workflow (huggingface/doc-builder/.github/workflows/upload_pr_documentation.yml at a pinned SHA) whose steps are not visible in this file, so the token scopes it requires cannot be read here; it likely needs little or nothing since it authenticates to the Hub and comments via separate secrets, but that must be verified in the called workflow.

Anything not listed above keeps the permissions it had. To measure a job this could not read, add GitHubSecurityLab/actions-permissions/monitor to it and run the workflow — it reports the minimum the run actually used.

Pinning changes come from pinact and are mechanical. Any other change was generated by Claude — read it before merging.

@HuggingFaceDocBuilderDev

Copy link
Copy Markdown

The docs for this PR live here. All of your documentation changes will be reflected on that endpoint. The docs are available until 30 days after the last update.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant