Skip to content

Scope GITHUB_TOKEN permissions per job - #841

Merged
paulinebm merged 1 commit into
mainfrom
security/scope-permissions
Sep 23, 2026
Merged

paulinebm merged 1 commit into
mainfrom
security/scope-permissions

Conversation

@hf-security-analysis

Copy link
Copy Markdown
Contributor

Workflow hardening

GITHUB_TOKEN permissions scoped per job

A workflow with no permissions: block inherits whatever the repository or the
organization hands out, which is commonly write access to everything. Any step
in that job — including one inside a third-party action — can then push commits,
open releases or edit issues with it.

Each block below grants a job the scopes its own steps need and nothing else.
Jobs that already declared their permissions were left untouched. The
workflow-level permissions: {} is only added once every job in the file
carries its own block, because on its own it would silently strip the jobs it
missed.

Workflow Job Granted
.github/workflows/build_kernel.yaml build contents: read
.github/workflows/build_kernel.yaml test contents: read
.github/workflows/build_kernel_cpu.yaml build contents: read
.github/workflows/build_kernel_macos.yaml build contents: read
.github/workflows/build_kernel_rocm.yaml build contents: read
.github/workflows/build_kernel_windows.yaml build contents: read
.github/workflows/build_kernel_xpu.yaml build contents: read
.github/workflows/check_variants.yaml build contents: read
.github/workflows/kernel-builder-cli-docs.yaml check-cli-docs contents: read
.github/workflows/lint.yml griffe contents: read
.github/workflows/lint.yml lint contents: read
.github/workflows/lint.yml validate-dependencies contents: read
.github/workflows/nix_checks.yml build contents: read
.github/workflows/publish_kernels.yml linux contents: read
.github/workflows/publish_kernels.yml macos contents: read
.github/workflows/publish_kernels.yml musllinux contents: read
.github/workflows/publish_kernels.yml sdist contents: read
.github/workflows/publish_kernels.yml windows contents: read
.github/workflows/rust.yaml clippy contents: read
.github/workflows/rust.yaml fmt contents: read
.github/workflows/rust.yaml test contents: read
.github/workflows/test_e2e.yaml cleanup none
.github/workflows/test_e2e.yaml download-and-test contents: read
.github/workflows/test_e2e.yaml init-build-upload contents: read
.github/workflows/test_extra_commands.yaml build contents: read
.github/workflows/update_abi_symbols.yaml update contents: read
.github/workflows/update_cache.yaml build contents: read
.github/workflows/vouch-check-pr.yaml check contents: read, pull-requests: write

Opened by the workflow security bot. It changes what this pull request says it
changes, and nothing else.

A job with no `permissions:` block inherits whatever the repository
hands out. Each block added here grants what that job's own steps
need and nothing more.
@github-actions

Copy link
Copy Markdown

Coverage report — kernels/

Measured on: Python 3.10 / Torch 2.13.0.
Other CI configurations are not included in this number.
Hardware-gated code paths (ROCm/XPU/NPU/Darwin/Windows) are excluded or unreachable on the Linux+CUDA runner.

Total coverage: 87.2% — threshold: 80% — ✅

Per-file breakdown
Name Stmts Miss Cover Missing
src/kernels/__init__.py 14 0 100%
src/kernels/_system.py 6 1 83% 10
src/kernels/_versions.py 130 14 89% 53, 59-60, 63-64, 102, 165-170, 199, 219
src/kernels/archs.py 56 1 98% 94
src/kernels/backends.py 213 62 71% 42, 46, 50-53, 70, 92, 110, 119, 123, 127-129, 150, 159, 163, 167-169, 190, 201, 203, 210-213, 226, 230, 234-254, 262, 285-305
src/kernels/compat.py 9 1 89% 5
src/kernels/deps.py 70 1 99% 56
src/kernels/hf_hub.py 63 2 97% 21, 23
src/kernels/importer.py 44 5 89% 80, 84, 87, 101-102
src/kernels/install.py 21 7 67% 76-100
src/kernels/layer/__init__.py 6 0 100%
src/kernels/layer/_interval_tree.py 103 4 96% 23, 52, 147, 150
src/kernels/layer/device.py 48 14 71% 42, 47-49, 91, 96-98, 101, 149, 152, 155-157
src/kernels/layer/func.py 85 6 93% 90, 115, 191, 311, 338, 368
src/kernels/layer/globals.py 5 0 100%
src/kernels/layer/kernelize.py 80 8 90% 258, 293, 301-302, 308, 312, 328-330
src/kernels/layer/layer.py 215 14 93% 182, 229, 256, 390, 470-471, 492, 500, 511, 540, 544, 557, 610, 640
src/kernels/layer/mode.py 14 0 100%
src/kernels/layer/repos.py 144 42 71% 27, 33, 36-43, 63-64, 70, 73-76, 90, 94, 103-104, 110, 113-116, 123-124, 130, 133-136, 143-144, 150, 153-156, 163-164, 170, 173-176, 257
src/kernels/load.py 71 2 97% 338, 378
src/kernels/locking.py 89 64 28% 35-83, 91-98, 102-125, 137, 152-159, 165-175, 179-186
src/kernels/python_deps.py 58 6 90% 59-60, 64-65, 101, 104
src/kernels/resolver.py 156 2 99% 220, 226
src/kernels/status.py 50 2 96% 25, 79
src/kernels/validate.py 88 5 94% 9, 100, 167, 190-191
src/kernels/variants.py 278 19 93% 65, 96, 117, 147, 256-257, 299-302, 304, 388-394, 400-406, 437-443, 455-461
src/kernels/verify.py 127 6 95% 46, 202-204, 318-319
TOTAL 2243 288 87%

Updated by the Test kernels workflow on commit ce2ac201d7c7473f4acc3e317c875e79816a4e53.

@paulinebm paulinebm left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved as part of the org-wide GITHUB_TOKEN permissions campaign.

@paulinebm
paulinebm merged commit f86e642 into main Sep 23, 2026
51 of 53 checks passed
@paulinebm
paulinebm deleted the security/scope-permissions branch September 23, 2026 12:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant