From f4a261bbb9597afb267fca01bf63dbc699e31086 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 21 Sep 2026 00:38:05 +0000 Subject: [PATCH 1/2] build(deps): bump the actions group across 1 directory with 9 updates Bumps the actions group with 9 updates in the / directory: | Package | From | To | | --- | --- | --- | | [huggingface/doc-builder/.github/workflows/build_main_documentation.yml](https://github.com/huggingface/doc-builder) | `7ccf6c02dc2e3aea1b07f6668f783b20c3bf407c` | `17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169` | | [DeterminateSystems/nix-installer-action](https://github.com/determinatesystems/nix-installer-action) | `22` | `23` | | [cachix/install-nix-action](https://github.com/cachix/install-nix-action) | `31.11.0` | `31.11.1` | | [Swatinem/rust-cache](https://github.com/swatinem/rust-cache) | `2.9.1` | `2.9.2` | | [huggingface/doc-builder/.github/workflows/build_pr_documentation.yml](https://github.com/huggingface/doc-builder) | `7ccf6c02dc2e3aea1b07f6668f783b20c3bf407c` | `17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169` | | [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) | `9.0.0` | `10.1.0` | | [pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish) | `1.14.1` | `1.14.2` | | [sigstore/gh-action-sigstore-python](https://github.com/sigstore/gh-action-sigstore-python) | `3.4.0` | `3.5.0` | | [huggingface/doc-builder/.github/workflows/upload_pr_documentation.yml](https://github.com/huggingface/doc-builder) | `7ccf6c02dc2e3aea1b07f6668f783b20c3bf407c` | `17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169` | Updates `huggingface/doc-builder/.github/workflows/build_main_documentation.yml` from 7ccf6c02dc2e3aea1b07f6668f783b20c3bf407c to 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169 - [Release notes](https://github.com/huggingface/doc-builder/releases) - [Changelog](https://github.com/huggingface/doc-builder/blob/main/RELEASE.md) - [Commits](https://github.com/huggingface/doc-builder/compare/7ccf6c02dc2e3aea1b07f6668f783b20c3bf407c...17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169) Updates `DeterminateSystems/nix-installer-action` from 22 to 23 - [Release notes](https://github.com/determinatesystems/nix-installer-action/releases) - [Commits](https://github.com/determinatesystems/nix-installer-action/compare/ef8a148080ab6020fd15196c2084a2eea5ff2d25...3138316df39ed29be04236d7ffc686fa525866aa) Updates `cachix/install-nix-action` from 31.11.0 to 31.11.1 - [Release notes](https://github.com/cachix/install-nix-action/releases) - [Changelog](https://github.com/cachix/install-nix-action/blob/master/RELEASE.md) - [Commits](https://github.com/cachix/install-nix-action/compare/630ae543ea3a38a9a4166f03376c02c50f408342...13d8dd58da0234aa297dedd986986ccb8e7f3e24) Updates `Swatinem/rust-cache` from 2.9.1 to 2.9.2 - [Release notes](https://github.com/swatinem/rust-cache/releases) - [Changelog](https://github.com/Swatinem/rust-cache/blob/master/CHANGELOG.md) - [Commits](https://github.com/swatinem/rust-cache/compare/c19371144df3bb44fab255c43d04cbc2ab54d1c4...6323deb102c322ba6fcbdcafc7e3dddab59af2b6) Updates `huggingface/doc-builder/.github/workflows/build_pr_documentation.yml` from 7ccf6c02dc2e3aea1b07f6668f783b20c3bf407c to 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169 - [Release notes](https://github.com/huggingface/doc-builder/releases) - [Changelog](https://github.com/huggingface/doc-builder/blob/main/RELEASE.md) - [Commits](https://github.com/huggingface/doc-builder/compare/7ccf6c02dc2e3aea1b07f6668f783b20c3bf407c...17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169) Updates `astral-sh/setup-uv` from 9.0.0 to 10.1.0 - [Release notes](https://github.com/astral-sh/setup-uv/releases) - [Commits](https://github.com/astral-sh/setup-uv/compare/c771a70e6277c0a99b617c7a806ffedaca235ff9...bec219d24cd3e171d82865faccec33120bb574f4) Updates `pypa/gh-action-pypi-publish` from 1.14.1 to 1.14.2 - [Release notes](https://github.com/pypa/gh-action-pypi-publish/releases) - [Commits](https://github.com/pypa/gh-action-pypi-publish/compare/ba38be9e461d3875417946c167d0b5f3d385a247...dc37677b2e1c63e2034f94d8a5b11f265b73ba33) Updates `sigstore/gh-action-sigstore-python` from 3.4.0 to 3.5.0 - [Release notes](https://github.com/sigstore/gh-action-sigstore-python/releases) - [Changelog](https://github.com/sigstore/gh-action-sigstore-python/blob/main/CHANGELOG.md) - [Commits](https://github.com/sigstore/gh-action-sigstore-python/compare/5b79a39c381910c090341a2c9b0bf022c8b387e1...790bc6befb9d733738f18d8f895854b453640ec9) Updates `huggingface/doc-builder/.github/workflows/upload_pr_documentation.yml` from 7ccf6c02dc2e3aea1b07f6668f783b20c3bf407c to 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169 - [Release notes](https://github.com/huggingface/doc-builder/releases) - [Changelog](https://github.com/huggingface/doc-builder/blob/main/RELEASE.md) - [Commits](https://github.com/huggingface/doc-builder/compare/7ccf6c02dc2e3aea1b07f6668f783b20c3bf407c...17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169) --- updated-dependencies: - dependency-name: huggingface/doc-builder/.github/workflows/build_main_documentation.yml dependency-version: 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169 dependency-type: direct:production dependency-group: actions - dependency-name: DeterminateSystems/nix-installer-action dependency-version: '23' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: cachix/install-nix-action dependency-version: 31.11.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions - dependency-name: Swatinem/rust-cache dependency-version: 2.9.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions - dependency-name: huggingface/doc-builder/.github/workflows/build_pr_documentation.yml dependency-version: 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169 dependency-type: direct:production dependency-group: actions - dependency-name: astral-sh/setup-uv dependency-version: 10.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: pypa/gh-action-pypi-publish dependency-version: 1.14.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions - dependency-name: sigstore/gh-action-sigstore-python dependency-version: 3.5.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: huggingface/doc-builder/.github/workflows/upload_pr_documentation.yml dependency-version: 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169 dependency-type: direct:production dependency-group: actions ... Signed-off-by: dependabot[bot] --- .github/workflows/build_documentation.yaml | 2 +- .github/workflows/build_kernel.yaml | 2 +- .github/workflows/build_kernel_cpu.yaml | 2 +- .github/workflows/build_kernel_macos.yaml | 2 +- .github/workflows/build_kernel_rocm.yaml | 2 +- .github/workflows/build_kernel_windows.yaml | 2 +- .github/workflows/build_kernel_xpu.yaml | 2 +- .github/workflows/build_pr_documentation.yaml | 2 +- .github/workflows/check_variants.yaml | 2 +- .github/workflows/lint.yml | 2 +- .github/workflows/nix_checks.yml | 2 +- .github/workflows/publish_kernels.yml | 6 +++--- .github/workflows/test_e2e.yaml | 6 +++--- .github/workflows/test_extra_commands.yaml | 2 +- .github/workflows/test_kernels.yaml | 2 +- .github/workflows/update_cache.yaml | 2 +- .github/workflows/upload_pr_documentation.yaml | 2 +- 17 files changed, 21 insertions(+), 21 deletions(-) diff --git a/.github/workflows/build_documentation.yaml b/.github/workflows/build_documentation.yaml index 53febf8d2..d2cfbf87d 100644 --- a/.github/workflows/build_documentation.yaml +++ b/.github/workflows/build_documentation.yaml @@ -13,7 +13,7 @@ on: jobs: build: - uses: huggingface/doc-builder/.github/workflows/build_main_documentation.yml@7ccf6c02dc2e3aea1b07f6668f783b20c3bf407c # main + uses: huggingface/doc-builder/.github/workflows/build_main_documentation.yml@17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169 # main with: commit_sha: ${{ github.sha }} package_path: kernels/kernels/ diff --git a/.github/workflows/build_kernel.yaml b/.github/workflows/build_kernel.yaml index eae52609e..0a5baea5f 100644 --- a/.github/workflows/build_kernel.yaml +++ b/.github/workflows/build_kernel.yaml @@ -28,7 +28,7 @@ jobs: group: ${{ matrix.runner }} steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - uses: DeterminateSystems/nix-installer-action@ef8a148080ab6020fd15196c2084a2eea5ff2d25 + - uses: DeterminateSystems/nix-installer-action@3138316df39ed29be04236d7ffc686fa525866aa with: extra-conf: | max-jobs = 8 diff --git a/.github/workflows/build_kernel_cpu.yaml b/.github/workflows/build_kernel_cpu.yaml index 3114a58f2..fa2f9f053 100644 --- a/.github/workflows/build_kernel_cpu.yaml +++ b/.github/workflows/build_kernel_cpu.yaml @@ -21,7 +21,7 @@ jobs: group: aws-highmemory-32-plus-nix steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - uses: DeterminateSystems/nix-installer-action@ef8a148080ab6020fd15196c2084a2eea5ff2d25 + - uses: DeterminateSystems/nix-installer-action@3138316df39ed29be04236d7ffc686fa525866aa with: extra-conf: | max-jobs = 4 diff --git a/.github/workflows/build_kernel_macos.yaml b/.github/workflows/build_kernel_macos.yaml index b30862f5e..4662586f5 100644 --- a/.github/workflows/build_kernel_macos.yaml +++ b/.github/workflows/build_kernel_macos.yaml @@ -24,7 +24,7 @@ jobs: - name: "Install Metal Toolchain" run: xcodebuild -downloadComponent metalToolchain - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0 + - uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1 - uses: cachix/cachix-action@1eb2ef646ac0255473d23a5907ad7b04ce94065c # v17 with: name: huggingface diff --git a/.github/workflows/build_kernel_rocm.yaml b/.github/workflows/build_kernel_rocm.yaml index 8f05922de..9c27b8374 100644 --- a/.github/workflows/build_kernel_rocm.yaml +++ b/.github/workflows/build_kernel_rocm.yaml @@ -21,7 +21,7 @@ jobs: group: aws-highmemory-32-plus-nix steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - uses: DeterminateSystems/nix-installer-action@ef8a148080ab6020fd15196c2084a2eea5ff2d25 + - uses: DeterminateSystems/nix-installer-action@3138316df39ed29be04236d7ffc686fa525866aa with: extra-conf: | max-jobs = 4 diff --git a/.github/workflows/build_kernel_windows.yaml b/.github/workflows/build_kernel_windows.yaml index 87b770408..77c94a981 100644 --- a/.github/workflows/build_kernel_windows.yaml +++ b/.github/workflows/build_kernel_windows.yaml @@ -113,7 +113,7 @@ jobs: # always writes target/ at the workspace root, so caching # ./kernel-builder/target would restore to a path cargo never reads. - name: Cache cargo + kernel-builder target - uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2.9.1 + uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 with: workspaces: . shared-key: kernel-builder-${{ matrix.os }} diff --git a/.github/workflows/build_kernel_xpu.yaml b/.github/workflows/build_kernel_xpu.yaml index e240aa2df..fde968e1d 100644 --- a/.github/workflows/build_kernel_xpu.yaml +++ b/.github/workflows/build_kernel_xpu.yaml @@ -21,7 +21,7 @@ jobs: group: aws-highmemory-32-plus-nix steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - uses: DeterminateSystems/nix-installer-action@ef8a148080ab6020fd15196c2084a2eea5ff2d25 + - uses: DeterminateSystems/nix-installer-action@3138316df39ed29be04236d7ffc686fa525866aa with: extra-conf: | max-jobs = 4 diff --git a/.github/workflows/build_pr_documentation.yaml b/.github/workflows/build_pr_documentation.yaml index 3255337bc..72fcf2cd8 100644 --- a/.github/workflows/build_pr_documentation.yaml +++ b/.github/workflows/build_pr_documentation.yaml @@ -13,7 +13,7 @@ concurrency: jobs: build: - uses: huggingface/doc-builder/.github/workflows/build_pr_documentation.yml@7ccf6c02dc2e3aea1b07f6668f783b20c3bf407c # main + uses: huggingface/doc-builder/.github/workflows/build_pr_documentation.yml@17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169 # main with: commit_sha: ${{ github.event.pull_request.head.sha }} pr_number: ${{ github.event.number }} diff --git a/.github/workflows/check_variants.yaml b/.github/workflows/check_variants.yaml index c51301e35..b999b3556 100644 --- a/.github/workflows/check_variants.yaml +++ b/.github/workflows/check_variants.yaml @@ -20,7 +20,7 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0 + - uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1 with: nix_path: nixpkgs=channel:nixos-unstable - name: Generate variants JSON diff --git a/.github/workflows/lint.yml b/.github/workflows/lint.yml index 7bd7962be..161fb9402 100644 --- a/.github/workflows/lint.yml +++ b/.github/workflows/lint.yml @@ -42,7 +42,7 @@ jobs: with: fetch-depth: 0 - name: Install uv and set the python version - uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0 + uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 with: python-version: "3.12" - name: Check for breaking changes diff --git a/.github/workflows/nix_checks.yml b/.github/workflows/nix_checks.yml index f0272cef4..cb78ec6fe 100644 --- a/.github/workflows/nix_checks.yml +++ b/.github/workflows/nix_checks.yml @@ -21,7 +21,7 @@ jobs: group: aws-highmemory-32-plus-nix steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - uses: DeterminateSystems/nix-installer-action@ef8a148080ab6020fd15196c2084a2eea5ff2d25 + - uses: DeterminateSystems/nix-installer-action@3138316df39ed29be04236d7ffc686fa525866aa with: extra-conf: | max-jobs = 4 diff --git a/.github/workflows/publish_kernels.yml b/.github/workflows/publish_kernels.yml index 0c42f7f7f..feba692e6 100644 --- a/.github/workflows/publish_kernels.yml +++ b/.github/workflows/publish_kernels.yml @@ -248,7 +248,7 @@ jobs: path: dist merge-multiple: true - name: Publish distribution 📦 to PyPI - uses: pypa/gh-action-pypi-publish@ba38be9e461d3875417946c167d0b5f3d385a247 # release/v1 + uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # release/v1 github-release: name: >- @@ -270,7 +270,7 @@ jobs: path: dist merge-multiple: true - name: Sign the dists with Sigstore - uses: sigstore/gh-action-sigstore-python@5b79a39c381910c090341a2c9b0bf022c8b387e1 # v3.4.0 + uses: sigstore/gh-action-sigstore-python@790bc6befb9d733738f18d8f895854b453640ec9 # v3.5.0 with: inputs: >- ./dist/*.tar.gz @@ -320,7 +320,7 @@ jobs: path: dist merge-multiple: true - name: Publish distribution 📦 to TestPyPI - uses: pypa/gh-action-pypi-publish@ba38be9e461d3875417946c167d0b5f3d385a247 # release/v1 + uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # release/v1 with: repository-url: https://test.pypi.org/legacy/ skip-existing: true # Only upload when the version is unique. diff --git a/.github/workflows/test_e2e.yaml b/.github/workflows/test_e2e.yaml index eed583c4c..337a9505a 100644 --- a/.github/workflows/test_e2e.yaml +++ b/.github/workflows/test_e2e.yaml @@ -34,7 +34,7 @@ jobs: variant: ${{ steps.variant.outputs.name }} steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - uses: DeterminateSystems/nix-installer-action@ef8a148080ab6020fd15196c2084a2eea5ff2d25 + - uses: DeterminateSystems/nix-installer-action@3138316df39ed29be04236d7ffc686fa525866aa with: extra-conf: | max-jobs = 8 @@ -119,7 +119,7 @@ jobs: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Install uv and set Python version - uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0 + uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 with: python-version: "3.12" @@ -158,7 +158,7 @@ jobs: if: always() runs-on: ubuntu-latest steps: - - uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0 + - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 with: python-version: "3.12" - name: Delete test repos diff --git a/.github/workflows/test_extra_commands.yaml b/.github/workflows/test_extra_commands.yaml index 7984f5708..aba224f5b 100644 --- a/.github/workflows/test_extra_commands.yaml +++ b/.github/workflows/test_extra_commands.yaml @@ -20,7 +20,7 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - uses: DeterminateSystems/nix-installer-action@ef8a148080ab6020fd15196c2084a2eea5ff2d25 + - uses: DeterminateSystems/nix-installer-action@3138316df39ed29be04236d7ffc686fa525866aa with: extra-conf: | max-jobs = 4 diff --git a/.github/workflows/test_kernels.yaml b/.github/workflows/test_kernels.yaml index dfd93e827..e6de0e9bb 100644 --- a/.github/workflows/test_kernels.yaml +++ b/.github/workflows/test_kernels.yaml @@ -40,7 +40,7 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Install uv and set the python version - uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0 + uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 with: python-version: ${{ matrix.python-version }} diff --git a/.github/workflows/update_cache.yaml b/.github/workflows/update_cache.yaml index e6423e15a..734caf2d5 100644 --- a/.github/workflows/update_cache.yaml +++ b/.github/workflows/update_cache.yaml @@ -22,7 +22,7 @@ jobs: group: ${{ matrix.runner }} steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - uses: DeterminateSystems/nix-installer-action@ef8a148080ab6020fd15196c2084a2eea5ff2d25 + - uses: DeterminateSystems/nix-installer-action@3138316df39ed29be04236d7ffc686fa525866aa with: extra-conf: | max-jobs = 8 diff --git a/.github/workflows/upload_pr_documentation.yaml b/.github/workflows/upload_pr_documentation.yaml index e9678a47f..5ad09b089 100644 --- a/.github/workflows/upload_pr_documentation.yaml +++ b/.github/workflows/upload_pr_documentation.yaml @@ -8,7 +8,7 @@ on: jobs: build: - uses: huggingface/doc-builder/.github/workflows/upload_pr_documentation.yml@7ccf6c02dc2e3aea1b07f6668f783b20c3bf407c # main + uses: huggingface/doc-builder/.github/workflows/upload_pr_documentation.yml@17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169 # main with: package_name: kernels secrets: From c2d5bf6fd1ac1de89f1dab56f70291b70c211034 Mon Sep 17 00:00:00 2001 From: "hf-security-analysis[bot]" <265538906+hf-security-analysis[bot]@users.noreply.github.com> Date: Mon, 21 Sep 2026 11:51:11 +0200 Subject: [PATCH 2/2] fix(ci): harden GitHub Actions workflows (#835) (#836) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Automated hardening of the workflow files flagged on #835. > [!WARNING] > **This narrows what the workflow can reach.** Job permissions were declared in `.github/workflows/build_kernel.yaml`, `.github/workflows/build_kernel_cpu.yaml`, `.github/workflows/build_kernel_macos.yaml`, `.github/workflows/build_kernel_rocm.yaml`, `.github/workflows/build_kernel_windows.yaml`, `.github/workflows/build_kernel_xpu.yaml`, `.github/workflows/check_variants.yaml`, `.github/workflows/lint.yml`, `.github/workflows/nix_checks.yml`, `.github/workflows/test_e2e.yaml`, `.github/workflows/test_extra_commands.yaml`, `.github/workflows/update_cache.yaml`. Each job now gets only the scopes its steps were read to need — if one of them does something this could not see, it will fail on the next run. The table below says which step drove each scope. Targets `dependabot/github_actions/actions-2436af7829`. Files changed, and what changed them: - `.github/workflows/build_kernel.yaml` — action pins; job permissions - `.github/workflows/build_kernel_cpu.yaml` — action pins; job permissions - `.github/workflows/build_kernel_macos.yaml` — job permissions - `.github/workflows/build_kernel_rocm.yaml` — action pins; job permissions - `.github/workflows/build_kernel_windows.yaml` — job permissions - `.github/workflows/build_kernel_xpu.yaml` — action pins; job permissions - `.github/workflows/check_variants.yaml` — job permissions - `.github/workflows/lint.yml` — job permissions - `.github/workflows/nix_checks.yml` — action pins; job permissions - `.github/workflows/publish_kernels.yml` — action pins - `.github/workflows/test_e2e.yaml` — action pins; job permissions - `.github/workflows/test_extra_commands.yaml` — action pins; job permissions - `.github/workflows/update_cache.yaml` — action pins; job permissions Fixed by this PR: - **HIGH** `unpinned-action` (pinact) — .github/workflows/build_kernel.yaml:31 - **HIGH** `unpinned-action` (pinact) — .github/workflows/build_kernel_cpu.yaml:24 - **HIGH** `unpinned-action` (pinact) — .github/workflows/build_kernel_rocm.yaml:24 - **HIGH** `unpinned-action` (pinact) — .github/workflows/build_kernel_xpu.yaml:24 - **HIGH** `unpinned-action` (pinact) — .github/workflows/nix_checks.yml:24 - **HIGH** `unpinned-action` (pinact) — .github/workflows/publish_kernels.yml:251 - **HIGH** `unpinned-action` (pinact) — .github/workflows/publish_kernels.yml:323 - **HIGH** `unpinned-action` (pinact) — .github/workflows/test_e2e.yaml:37 - **HIGH** `unpinned-action` (pinact) — .github/workflows/test_extra_commands.yaml:23 - **HIGH** `unpinned-action` (pinact) — .github/workflows/update_cache.yaml:25 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/build_kernel.yaml:1 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/build_kernel.yaml:18 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/build_kernel.yaml:69 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/build_kernel_cpu.yaml:1 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/build_kernel_cpu.yaml:18 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/build_kernel_macos.yaml:1 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/build_kernel_macos.yaml:18 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/build_kernel_rocm.yaml:1 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/build_kernel_rocm.yaml:18 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/build_kernel_windows.yaml:1 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/build_kernel_windows.yaml:18 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/build_kernel_xpu.yaml:1 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/build_kernel_xpu.yaml:18 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/check_variants.yaml:1 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/check_variants.yaml:18 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/lint.yml:1 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/lint.yml:18 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/lint.yml:35 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/lint.yml:51 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/nix_checks.yml:1 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/nix_checks.yml:18 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/test_e2e.yaml:1 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/test_e2e.yaml:29 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/test_e2e.yaml:111 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/test_e2e.yaml:155 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/test_extra_commands.yaml:1 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/test_extra_commands.yaml:18 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/update_cache.yaml:1 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/update_cache.yaml:12 **This does not fix everything.** 10 further finding(s) (2 critical, 1 high, 7 medium) need a decision this bot should not make for you. They are in the security channel with their locations — deliberately not repeated here, since this repository may be public and they are not fixed yet. ### Permissions `.github/workflows/build_documentation.yaml` > `build` was left as it is — This job only calls the external reusable workflow huggingface/doc-builder/.github/workflows/build_main_documentation.yml, whose jobs and steps are not in this file, so the token scopes it requires cannot be determined here. `.github/workflows/build_kernel.yaml` | job | granted | why | |---|---|---| | `build` | `contents: read` | actions/checkout needs contents: read; the nix-installer, cachix (authenticated via a secret, not the GITHUB_TOKEN) and upload-artifact steps in the same run require no token scopes. | | `test` | `contents: read` | actions/checkout needs contents: read; download-artifact pulls an artifact produced by the build job in the same run, and the docker build/run steps use no GitHub API. | `.github/workflows/build_kernel_cpu.yaml` | job | granted | why | |---|---|---| | `build` | `contents: read` | Only actions/checkout needs the token (contents: read); the nix-installer, cachix (which uses a secret, not the GITHUB_TOKEN), and the nix build/test steps make no GitHub API writes. | `.github/workflows/build_kernel_macos.yaml` | job | granted | why | |---|---|---| | `build` | `contents: read` | Only actions/checkout needs the token (contents: read); the Nix/Cachix steps and Metal build just compile code and the cachix auth token is a secret, not a token scope. | `.github/workflows/build_kernel_rocm.yaml` | job | granted | why | |---|---|---| | `build` | `contents: read` | Only actions/checkout needs the token (contents: read); the nix-installer and cachix steps authenticate via a secret, not the GITHUB_TOKEN, and the nix build steps use no API access. | `.github/workflows/build_kernel_windows.yaml` | job | granted | why | |---|---|---| | `build` | `contents: read` | Only actions/checkout needs the token (contents: read); the remaining steps are CUDA/Rust/Python toolchain setup, cache actions (which use the cache service, not the token) and local compilation — note the nix-builder\scripts\windows\builder.ps1 build script is not in this file, but its invocation is a plain kernel build with no API usage. | `.github/workflows/build_kernel_xpu.yaml` | job | granted | why | |---|---|---| | `build` | `contents: read` | Only `actions/checkout` needs the token (contents: read); the nix-installer, cachix (authenticated via a secret, not the GITHUB_TOKEN) and `nix build` steps make no GitHub API writes. | `.github/workflows/build_pr_documentation.yaml` > `build` was left as it is — This job only calls the external reusable workflow huggingface/doc-builder/.github/workflows/build_pr_documentation.yml, whose job definitions are not in this file, so the required token scopes cannot be read here. `.github/workflows/check_variants.yaml` | job | granted | why | |---|---|---| | `build` | `contents: read` | Only actions/checkout needs the token (contents: read); the remaining steps run nix evaluations, git diff, and a local script (nix-builder/scripts/gen_variants_markdown.py, whose contents aren't in this file but which only regenerates a tracked markdown file for comparison) without any API calls or pushes. | `.github/workflows/lint.yml` | job | granted | why | |---|---|---| | `lint` | `contents: read` | Only actions/checkout plus ruff-action lint/format checks that operate on local files, so contents: read is sufficient. | | `griffe` | `contents: read` | actions/checkout with fetch-depth: 0 and a local uvx griffe API-diff run against the main ref; no API writes, so contents: read. | | `validate-dependencies` | `contents: read` | actions/checkout followed by a local diff of two checked-out files needs only contents: read. | `.github/workflows/nix_checks.yml` | job | granted | why | |---|---|---| | `build` | `contents: read` | Only actions/checkout needs the token (contents: read); the nix-installer and cachix actions authenticate via their own inputs/secrets and the remaining steps just run `nix fmt`/`nix build` locally, so no write scopes are needed. | `.github/workflows/test_e2e.yaml` | job | granted | why | |---|---|---| | `init-build-upload` | `contents: read` | actions/checkout needs contents: read; the nix build/upload steps push artifacts to the Hugging Face Hub using HF_TOKEN, not the GitHub token, so no write scopes are required (cachix and nix-installer actions use their own secrets). | | `download-and-test` | `contents: read` | actions/checkout needs contents: read; setup-uv and dtolnay/rust-toolchain only download public tooling and the test step pulls the kernel from the HF Hub, requiring no GitHub token scopes. | | `cleanup` | `{}` — nothing | No checkout and no GitHub API use — the only step deletes Hugging Face Hub repos via huggingface_hub with HF_TOKEN, so no GITHUB_TOKEN scopes are needed (setup-uv only fetches public release assets). | `.github/workflows/test_extra_commands.yaml` | job | granted | why | |---|---|---| | `build` | `contents: read` | actions/checkout needs contents: read; the nix-installer and cachix actions only fetch installers/binary caches (cachix uses its own auth token, not GITHUB_TOKEN), and the two nix run steps just build/test locally, so no write scopes are required. | `.github/workflows/test_kernels.yaml` | job | granted | why | |---|---|---| | `build` | `contents: read` | Only actions/checkout needs the token (contents: read); the test, mypy, coverage-rendering and actions/upload-artifact steps all operate on the checked-out tree within the same run, so the workflow's declared packages: write is unnecessary — the PR comment is posted by a separate downstream workflow_run workflow, not here. | `.github/workflows/update_cache.yaml` | job | granted | why | |---|---|---| | `build` | `contents: read` | Only actions/checkout needs the token (contents: read); the nix-installer and cachix steps authenticate to Cachix with a secret, not the GITHUB_TOKEN, and `nix build` just builds locally. | `.github/workflows/upload_pr_documentation.yaml` > `build` was left as it is — This job only declares `uses:` to call an external reusable workflow (huggingface/doc-builder/.github/workflows/upload_pr_documentation.yml) that is not in this file, so its token needs cannot be read here; based on the workflow_run trigger and comment_bot_token input it likely needs at least `actions: read` to fetch the triggering run's artifacts and `pull-requests: write` to post a docs preview comment — verify against the pinned doc-builder workflow. Anything not listed above keeps the permissions it had. To measure a job this could not read, add [`GitHubSecurityLab/actions-permissions/monitor`](https://github.com/GitHubSecurityLab/actions-permissions) to it and run the workflow — it reports the minimum the run actually used. Pinning changes come from `pinact` and are mechanical. Any other change was generated by Claude — read it before merging. Co-authored-by: hf-security-analysis[bot] <265538906+hf-security-analysis[bot]@users.noreply.github.com> --- .github/workflows/build_kernel.yaml | 8 +++++++- .github/workflows/build_kernel_cpu.yaml | 6 +++++- .github/workflows/build_kernel_macos.yaml | 4 ++++ .github/workflows/build_kernel_rocm.yaml | 6 +++++- .github/workflows/build_kernel_windows.yaml | 4 ++++ .github/workflows/build_kernel_xpu.yaml | 6 +++++- .github/workflows/check_variants.yaml | 4 ++++ .github/workflows/lint.yml | 8 ++++++++ .github/workflows/nix_checks.yml | 6 +++++- .github/workflows/publish_kernels.yml | 4 ++-- .github/workflows/test_e2e.yaml | 9 ++++++++- .github/workflows/test_extra_commands.yaml | 6 +++++- .github/workflows/update_cache.yaml | 6 +++++- 13 files changed, 67 insertions(+), 10 deletions(-) diff --git a/.github/workflows/build_kernel.yaml b/.github/workflows/build_kernel.yaml index 0a5baea5f..fbcf0bd2c 100644 --- a/.github/workflows/build_kernel.yaml +++ b/.github/workflows/build_kernel.yaml @@ -14,8 +14,12 @@ concurrency: group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} cancel-in-progress: true +permissions: {} + jobs: build: + permissions: + contents: read name: Build kernels (${{ matrix.arch }}) strategy: matrix: @@ -28,7 +32,7 @@ jobs: group: ${{ matrix.runner }} steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - uses: DeterminateSystems/nix-installer-action@3138316df39ed29be04236d7ffc686fa525866aa + - uses: DeterminateSystems/nix-installer-action@3138316df39ed29be04236d7ffc686fa525866aa # v23 with: extra-conf: | max-jobs = 8 @@ -67,6 +71,8 @@ jobs: silu-and-mul-kernel test: + permissions: + contents: read name: Test kernels (UBI ${{ matrix.ubi_version }}) needs: build strategy: diff --git a/.github/workflows/build_kernel_cpu.yaml b/.github/workflows/build_kernel_cpu.yaml index fa2f9f053..461427113 100644 --- a/.github/workflows/build_kernel_cpu.yaml +++ b/.github/workflows/build_kernel_cpu.yaml @@ -14,14 +14,18 @@ concurrency: group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} cancel-in-progress: true +permissions: {} + jobs: build: + permissions: + contents: read name: Build kernel runs-on: group: aws-highmemory-32-plus-nix steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - uses: DeterminateSystems/nix-installer-action@3138316df39ed29be04236d7ffc686fa525866aa + - uses: DeterminateSystems/nix-installer-action@3138316df39ed29be04236d7ffc686fa525866aa # v23 with: extra-conf: | max-jobs = 4 diff --git a/.github/workflows/build_kernel_macos.yaml b/.github/workflows/build_kernel_macos.yaml index 4662586f5..d4b0d39a8 100644 --- a/.github/workflows/build_kernel_macos.yaml +++ b/.github/workflows/build_kernel_macos.yaml @@ -14,8 +14,12 @@ concurrency: group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} cancel-in-progress: true +permissions: {} + jobs: build: + permissions: + contents: read name: Build kernel runs-on: macos-26 steps: diff --git a/.github/workflows/build_kernel_rocm.yaml b/.github/workflows/build_kernel_rocm.yaml index 9c27b8374..323a2bde5 100644 --- a/.github/workflows/build_kernel_rocm.yaml +++ b/.github/workflows/build_kernel_rocm.yaml @@ -14,14 +14,18 @@ concurrency: group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} cancel-in-progress: true +permissions: {} + jobs: build: + permissions: + contents: read name: Build kernels (ROCm) runs-on: group: aws-highmemory-32-plus-nix steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - uses: DeterminateSystems/nix-installer-action@3138316df39ed29be04236d7ffc686fa525866aa + - uses: DeterminateSystems/nix-installer-action@3138316df39ed29be04236d7ffc686fa525866aa # v23 with: extra-conf: | max-jobs = 4 diff --git a/.github/workflows/build_kernel_windows.yaml b/.github/workflows/build_kernel_windows.yaml index 77c94a981..ef703f4be 100644 --- a/.github/workflows/build_kernel_windows.yaml +++ b/.github/workflows/build_kernel_windows.yaml @@ -14,8 +14,12 @@ concurrency: group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} cancel-in-progress: true +permissions: {} + jobs: build: + permissions: + contents: read strategy: matrix: os: [ windows-2022 ] diff --git a/.github/workflows/build_kernel_xpu.yaml b/.github/workflows/build_kernel_xpu.yaml index fde968e1d..3427ee191 100644 --- a/.github/workflows/build_kernel_xpu.yaml +++ b/.github/workflows/build_kernel_xpu.yaml @@ -14,14 +14,18 @@ concurrency: group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} cancel-in-progress: true +permissions: {} + jobs: build: + permissions: + contents: read name: Build kernel runs-on: group: aws-highmemory-32-plus-nix steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - uses: DeterminateSystems/nix-installer-action@3138316df39ed29be04236d7ffc686fa525866aa + - uses: DeterminateSystems/nix-installer-action@3138316df39ed29be04236d7ffc686fa525866aa # v23 with: extra-conf: | max-jobs = 4 diff --git a/.github/workflows/check_variants.yaml b/.github/workflows/check_variants.yaml index b999b3556..27f0ec491 100644 --- a/.github/workflows/check_variants.yaml +++ b/.github/workflows/check_variants.yaml @@ -14,8 +14,12 @@ concurrency: group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} cancel-in-progress: true +permissions: {} + jobs: build: + permissions: + contents: read name: Check build variants runs-on: ubuntu-latest steps: diff --git a/.github/workflows/lint.yml b/.github/workflows/lint.yml index 161fb9402..05c59b8ac 100644 --- a/.github/workflows/lint.yml +++ b/.github/workflows/lint.yml @@ -14,8 +14,12 @@ env: RUFF_VERSION: "0.15.10" GRIFFE_VERSION: "1.15.0" +permissions: {} + jobs: lint: + permissions: + contents: read name: Run lints runs-on: ubuntu-latest steps: @@ -33,6 +37,8 @@ jobs: args: format --check griffe: + permissions: + contents: read name: Check API compatibility runs-on: ubuntu-latest env: @@ -49,6 +55,8 @@ jobs: run: uvx griffe==${{ env.GRIFFE_VERSION }} check kernels --search kernels/src -a main validate-dependencies: + permissions: + contents: read name: Validate python_depends.json runs-on: ubuntu-latest steps: diff --git a/.github/workflows/nix_checks.yml b/.github/workflows/nix_checks.yml index cb78ec6fe..918726928 100644 --- a/.github/workflows/nix_checks.yml +++ b/.github/workflows/nix_checks.yml @@ -14,14 +14,18 @@ concurrency: group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} cancel-in-progress: true +permissions: {} + jobs: build: + permissions: + contents: read name: Nix checks runs-on: group: aws-highmemory-32-plus-nix steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - uses: DeterminateSystems/nix-installer-action@3138316df39ed29be04236d7ffc686fa525866aa + - uses: DeterminateSystems/nix-installer-action@3138316df39ed29be04236d7ffc686fa525866aa # v23 with: extra-conf: | max-jobs = 4 diff --git a/.github/workflows/publish_kernels.yml b/.github/workflows/publish_kernels.yml index feba692e6..1894bed0c 100644 --- a/.github/workflows/publish_kernels.yml +++ b/.github/workflows/publish_kernels.yml @@ -248,7 +248,7 @@ jobs: path: dist merge-multiple: true - name: Publish distribution 📦 to PyPI - uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # release/v1 + uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # v1.14.2 github-release: name: >- @@ -320,7 +320,7 @@ jobs: path: dist merge-multiple: true - name: Publish distribution 📦 to TestPyPI - uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # release/v1 + uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # v1.14.2 with: repository-url: https://test.pypi.org/legacy/ skip-existing: true # Only upload when the version is unique. diff --git a/.github/workflows/test_e2e.yaml b/.github/workflows/test_e2e.yaml index 337a9505a..239ef556b 100644 --- a/.github/workflows/test_e2e.yaml +++ b/.github/workflows/test_e2e.yaml @@ -25,8 +25,12 @@ env: E2E_REPO_NAME: kernels-e2e-${{ github.run_id }}-${{ github.run_attempt }} E2E_PKG_NAME: kernels_e2e_${{ github.run_id }}_${{ github.run_attempt }} +permissions: {} + jobs: init-build-upload: + permissions: + contents: read name: Init, build, and upload kernel runs-on: group: aws-highmemory-32-plus-nix @@ -34,7 +38,7 @@ jobs: variant: ${{ steps.variant.outputs.name }} steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - uses: DeterminateSystems/nix-installer-action@3138316df39ed29be04236d7ffc686fa525866aa + - uses: DeterminateSystems/nix-installer-action@3138316df39ed29be04236d7ffc686fa525866aa # v23 with: extra-conf: | max-jobs = 8 @@ -109,6 +113,8 @@ jobs: nix run $GITHUB_WORKSPACE#kernel-builder -- upload /tmp/${{ env.E2E_REPO_NAME }} --repo-type model download-and-test: + permissions: + contents: read name: Download and test kernel via get_kernel needs: init-build-upload runs-on: @@ -153,6 +159,7 @@ jobs: " cleanup: + permissions: {} name: Clean up test repos needs: [init-build-upload, download-and-test] if: always() diff --git a/.github/workflows/test_extra_commands.yaml b/.github/workflows/test_extra_commands.yaml index aba224f5b..adb4344b6 100644 --- a/.github/workflows/test_extra_commands.yaml +++ b/.github/workflows/test_extra_commands.yaml @@ -14,13 +14,17 @@ concurrency: group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} cancel-in-progress: true +permissions: {} + jobs: build: + permissions: + contents: read name: Build kernel runs-on: ubuntu-latest steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - uses: DeterminateSystems/nix-installer-action@3138316df39ed29be04236d7ffc686fa525866aa + - uses: DeterminateSystems/nix-installer-action@3138316df39ed29be04236d7ffc686fa525866aa # v23 with: extra-conf: | max-jobs = 4 diff --git a/.github/workflows/update_cache.yaml b/.github/workflows/update_cache.yaml index 734caf2d5..693601ec8 100644 --- a/.github/workflows/update_cache.yaml +++ b/.github/workflows/update_cache.yaml @@ -8,8 +8,12 @@ concurrency: group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} cancel-in-progress: true +permissions: {} + jobs: build: + permissions: + contents: read name: Update Nix builder cache (${{ matrix.arch }}) strategy: matrix: @@ -22,7 +26,7 @@ jobs: group: ${{ matrix.runner }} steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - uses: DeterminateSystems/nix-installer-action@3138316df39ed29be04236d7ffc686fa525866aa + - uses: DeterminateSystems/nix-installer-action@3138316df39ed29be04236d7ffc686fa525866aa # v23 with: extra-conf: | max-jobs = 8