Skip to content

fix(ci): harden GitHub Actions workflows (#108) - #109

Merged
paulinebm merged 1 commit into
dependabot/github_actions/actions-1b9e9c7f05from
security/workflow-hardening/pr-108
Sep 29, 2026
Merged

paulinebm merged 1 commit into
dependabot/github_actions/actions-1b9e9c7f05from
security/workflow-hardening/pr-108

Conversation

@hf-security-analysis

@hf-security-analysis hf-security-analysis Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Automated hardening of the workflow files flagged on #108.

Targets dependabot/github_actions/actions-1b9e9c7f05. Files changed, and what changed them:

  • .github/workflows/CI.yml — action pins

Fixed by this PR:

  • HIGH unpinned-action (pinact) — .github/workflows/CI.yml:47
  • HIGH unpinned-action (pinact) — .github/workflows/CI.yml:63
  • HIGH unpinned-action (pinact) — .github/workflows/CI.yml:105
  • HIGH unpinned-action (pinact) — .github/workflows/CI.yml:112
  • HIGH unpinned-action (pinact) — .github/workflows/CI.yml:142
  • HIGH unpinned-action (pinact) — .github/workflows/CI.yml:176
  • HIGH unpinned-action (pinact) — .github/workflows/CI.yml:182
  • HIGH unpinned-action (pinact) — .github/workflows/CI.yml:200
  • HIGH unpinned-action (pinact) — .github/workflows/CI.yml:230

This does not fix everything. 1 further finding(s) (1 medium) need a decision this bot should not make for you. They are in the security channel with their locations — deliberately not repeated here, since this repository may be public and they are not fixed yet.

Permissions

.github/workflows/audit.yml

job granted why
audit contents: read, issues: write actions/checkout needs contents: read, and actions-rust-lang/audit opens or updates issues for found advisories on scheduled/non-PR runs, which needs issues: write (the reviewer may confirm the audit action's issue-creation behaviour).

Anything not listed above keeps the permissions it had. To measure a job this could not read, add GitHubSecurityLab/actions-permissions/monitor to it and run the workflow — it reports the minimum the run actually used.

Pinning changes come from pinact and are mechanical. Any other change was generated by Claude — read it before merging.

@paulinebm
paulinebm merged commit 8f15cf0 into dependabot/github_actions/actions-1b9e9c7f05 Sep 29, 2026
3 of 15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant