Skip to content

fix(ci): harden GitHub Actions workflows (#212) - #213

Open
hf-security-analysis[bot] wants to merge 1 commit into
dependabot/github_actions/actions-b04132cfd5from
security/workflow-hardening/pr-212
Open

hf-security-analysis[bot] wants to merge 1 commit into
dependabot/github_actions/actions-b04132cfd5from
security/workflow-hardening/pr-212

Conversation

@hf-security-analysis

@hf-security-analysis hf-security-analysis Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Automated hardening of the workflow files flagged on #212.

Targets dependabot/github_actions/actions-b04132cfd5. Files changed, and what changed them:

  • .github/workflows/claude-code-review.yml — action pins
  • .github/workflows/claude.yml — auth gate, llm injection

Fixed by this PR:

  • HIGH unpinned-action (pinact) — .github/workflows/claude-code-review.yml:36
  • HIGH broken_auth_gate (claude) — .github/workflows/claude.yml
  • HIGH llm_prompt_injection (claude) — .github/workflows/claude.yml

This does not fix everything. 2 further finding(s) (2 medium) need a decision this bot should not make for you. They are in the security channel with their locations — deliberately not repeated here, since this repository may be public and they are not fixed yet.

Permissions

.github/workflows/claude-code-review.yml

job granted why
claude-review contents: read, id-token: write, issues: read, pull-requests: read actions/checkout needs contents: read; the anthropics/claude-code-action review step reads PR/issue metadata (pull-requests: read, issues: read) and requests an OIDC token for Anthropic API auth (id-token: write) — note that if the code-review plugin is configured to post its findings back as a PR comment, that step would additionally require pull-requests: write.

.github/workflows/claude.yml

job granted why
claude actions: read, contents: read, id-token: write, issues: read, pull-requests: read actions/checkout needs contents: read; the anthropics/claude-code-action step reads issue/PR context (issues/pull-requests: read), reads CI results via its declared additional_permissions (actions: read) and performs an OIDC token exchange (id-token: write) — note that if this action ends up posting its tracking comment with GITHUB_TOKEN rather than an app token, issues and pull-requests would need to be write instead of read, so check that step first if it fails.

Anything not listed above keeps the permissions it had. To measure a job this could not read, add GitHubSecurityLab/actions-permissions/monitor to it and run the workflow — it reports the minimum the run actually used.

Pinning changes come from pinact and are mechanical. Any other change was generated by Claude — read it before merging.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants