Skip to content

fix(ci): harden GitHub Actions workflows (#2391) - #2409

Closed
hf-security-analysis[bot] wants to merge 36 commits into
feat/train_encode_splitfrom
security/workflow-hardening/pr-2391
Closed

hf-security-analysis[bot] wants to merge 36 commits into
feat/train_encode_splitfrom
security/workflow-hardening/pr-2391

Conversation

@hf-security-analysis

@hf-security-analysis hf-security-analysis Bot commented Sep 15, 2026

Copy link
Copy Markdown
Contributor

Automated hardening of the workflow files flagged on #2391.

Targets feat/rework-python-bindings. Files changed:

  • .github/workflows/python.yml

Fixed by this PR:

  • HIGH unpinned-action (pinact) — .github/workflows/python.yml:76
  • HIGH unpinned-action (pinact) — .github/workflows/python.yml:86
  • HIGH unpinned-action (pinact) — .github/workflows/python.yml:128

Reported on the pull request but not fixed here — each needs a decision this bot should not make for you:

  • CRITICAL impostor-commit (zizmor) — .github/workflows/python.yml:26
  • CRITICAL impostor-commit (zizmor) — .github/workflows/python.yml:60
  • CRITICAL impostor-commit (zizmor) — .github/workflows/python.yml:112
  • CRITICAL impostor-commit (zizmor) — .github/workflows/python.yml:161

Pinning changes come from pinact and are mechanical. Any other change was generated by Claude — read it before merging.

Base automatically changed from feat/rework-python-bindings to feat/train_encode_split September 15, 2026 15:24
@paulinebm

Copy link
Copy Markdown
Contributor

Closing this — its diff no longer describes the fix it was opened for.

This pull request was opened against feat/rework-python-bindings. That branch has since been merged and deleted, so GitHub retargeted this onto its own base, feat/train_encode_split. What it now proposes is the whole of the former branch (109 files, -24,197 lines), not the workflow hardening it was created to carry.

The bot has been fixed: a fix PR whose base branch has moved under it is now closed automatically rather than left with a meaningless diff. Sorry for the noise.

@paulinebm paulinebm closed this Sep 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants