Skip to content

fix(ci): harden GitHub Actions workflows (#2391) - #2406

Merged
SBrandeis merged 1 commit into
feat/rework-python-bindingsfrom
security/workflow-hardening/pr-2391
Sep 15, 2026
Merged

SBrandeis merged 1 commit into
feat/rework-python-bindingsfrom
security/workflow-hardening/pr-2391

Conversation

@hf-security-analysis

@hf-security-analysis hf-security-analysis Bot commented Sep 15, 2026 •

Copy link
Copy Markdown
Contributor

Automated hardening of the workflow files flagged on #2391.

Warning

This narrows what the workflow can reach. Job permissions were declared in .github/workflows/python.yml. Each job now gets only the scopes its steps were read to need — if one of them does something this could not see, it will fail on the next run. The table below says which step drove each scope.

Targets feat/rework-python-bindings. Files changed:

  • .github/workflows/python.yml

Fixed by this PR:

  • MEDIUM excessive-permissions (zizmor) — .github/workflows/python.yml:1
  • MEDIUM excessive-permissions (zizmor) — .github/workflows/python.yml:14
  • MEDIUM excessive-permissions (zizmor) — .github/workflows/python.yml:36
  • MEDIUM excessive-permissions (zizmor) — .github/workflows/python.yml:93
  • MEDIUM excessive-permissions (zizmor) — .github/workflows/python.yml:140

Reported on the pull request but not fixed here — each needs a decision this bot should not make for you:

  • CRITICAL impostor-commit (zizmor) — .github/workflows/python.yml:22
  • CRITICAL impostor-commit (zizmor) — .github/workflows/python.yml:54
  • CRITICAL impostor-commit (zizmor) — .github/workflows/python.yml:104
  • CRITICAL impostor-commit (zizmor) — .github/workflows/python.yml:151
  • HIGH unpinned-uses (zizmor) — .github/workflows/python.yml:70
  • HIGH unpinned-uses (zizmor) — .github/workflows/python.yml:120

Permissions

.github/workflows/python.yml

job granted why
build_win_32 contents: read Only actions/checkout plus toolchain/Python setup and a cargo build, so read access to the repository is all the token needs.
build_and_test contents: read Checkout is the only token-using step; rust-cache/actions-cache and the make test run only read the checked-out code (the HF_TOKEN secret is unrelated to token scopes).
quality contents: read Checkout drives the widest scope: clippy, make check-style and git diff --exit-code only inspect the local working tree and never push or report back to GitHub.
audit contents: read Checkout plus cargo install cargo-audit and cargo audit, which write no results back to GitHub (no SARIF upload), so only repository read is required.

Anything not listed above keeps the permissions it had. To measure a job this could not read, add GitHubSecurityLab/actions-permissions/monitor to it and run the workflow — it reports the minimum the run actually used.

Pinning changes come from pinact and are mechanical. Any other change was generated by Claude — read it before merging.

@SBrandeis
SBrandeis merged commit 504cca8 into feat/rework-python-bindings Sep 15, 2026
40 of 44 checks passed
@SBrandeis
SBrandeis deleted the security/workflow-hardening/pr-2391 branch September 15, 2026 14:20
SBrandeis added a commit that referenced this pull request Sep 15, 2026
* wip: new python bindings

* document copy on access

* ai: return np.ndarray from encoding + mechanical improvements

* partialeq + hash on padding arguments

* improve

* move python_v2 -> python

* update Python CI

* add free-threaded python back

* multiprocess + ft tests

* bump version + rm comments

* lint

* error out when the Padding Mutex is poisonned

* fixes

* skip pickle tests for now

* Encoding: support both native python list and numpy array as output

* wip: pickling

* mutliprocess v2

* re-add stub-gen bin

* Add from_pretrained

* refactor tests

* test padding left

* materialize padding in the Rust side

* lint

* ignore ty

* padding and options

* lint

* add a header in the generated python stubs

* fix(ci): harden workflow files flagged on #2391 (#2406)

Co-authored-by: hf-security-analysis[bot] <265538906+hf-security-analysis[bot]@users.noreply.github.com>

* rust only, no python source code

* clippy go

* lint

---------

Co-authored-by: hf-security-analysis[bot] <265538906+hf-security-analysis[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant