Skip to content

fix(ci): harden GitHub Actions workflows (#2391) - #2407

Closed
hf-security-analysis[bot] wants to merge 0 commit into
feat/rework-python-bindingsfrom
security/workflow-hardening/pr-2391
Closed

hf-security-analysis[bot] wants to merge 0 commit into
feat/rework-python-bindingsfrom
security/workflow-hardening/pr-2391

Conversation

@hf-security-analysis

@hf-security-analysis hf-security-analysis Bot commented Sep 15, 2026

Copy link
Copy Markdown
Contributor

Automated hardening of the workflow files flagged on #2391.

Targets feat/rework-python-bindings. Files changed:

  • .github/workflows/python.yml

Fixed by this PR:

  • HIGH unpinned-action (pinact) — .github/workflows/python.yml:76
  • HIGH unpinned-action (pinact) — .github/workflows/python.yml:86
  • HIGH unpinned-action (pinact) — .github/workflows/python.yml:128

Reported on the pull request but not fixed here — each needs a decision this bot should not make for you:

  • CRITICAL impostor-commit (zizmor) — .github/workflows/python.yml:26
  • CRITICAL impostor-commit (zizmor) — .github/workflows/python.yml:60
  • CRITICAL impostor-commit (zizmor) — .github/workflows/python.yml:112
  • CRITICAL impostor-commit (zizmor) — .github/workflows/python.yml:161

Pinning changes come from pinact and are mechanical. Any other change was generated by Claude — read it before merging.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants