Skip to content

fix(ci): harden GitHub Actions workflows (#14827) - #14828

Closed
hf-security-analysis[bot] wants to merge 0 commit into
fail-copy-statements-missingfrom
security/workflow-hardening/pr-14827
Closed

hf-security-analysis[bot] wants to merge 0 commit into
fail-copy-statements-missingfrom
security/workflow-hardening/pr-14827

Conversation

@hf-security-analysis

@hf-security-analysis hf-security-analysis Bot commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

Automated hardening of the workflow files flagged on #14827.

Warning

This changes when the workflow runs. Triggers or workflow-level settings were rewritten in .github/workflows/check_missing_copies.yml. A pull_request_target rewritten to pull_request is the correct fix for the finding and also drops the job's access to secrets — confirm that is what you want before merging.

Targets fail-copy-statements-missing. Files changed, and what changed them:

  • .github/workflows/check_missing_copies.yml — dangerous trigger

Fixed by this PR:

  • HIGH dangerous-triggers (zizmor) — .github/workflows/check_missing_copies.yml:3

Pinning changes come from pinact and are mechanical. Any other change was generated by Claude — read it before merging.

@github-actions github-actions Bot added CI size/S PR with diff < 50 LOC labels Sep 21, 2026
@hf-security-analysis
hf-security-analysis Bot force-pushed the security/workflow-hardening/pr-14827 branch from 9a38bd6 to b284fb6 Compare September 21, 2026 10:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CI size/S PR with diff < 50 LOC

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants