Skip to content

fix(ci): harden GitHub Actions workflows (#776) - #844

Merged
paulinebm merged 1 commit into
kernel-port-toolfrom
security/workflow-hardening/pr-776
Sep 23, 2026
Merged

paulinebm merged 1 commit into
kernel-port-toolfrom
security/workflow-hardening/pr-776

Conversation

@hf-security-analysis

@hf-security-analysis hf-security-analysis Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Automated hardening of the workflow files flagged on #776.

Warning

This narrows what the workflow can reach. Job permissions were declared in .github/workflows/rust.yaml. Each job now gets only the scopes its steps were read to need — if one of them does something this could not see, it will fail on the next run. The table below says which step drove each scope.

Targets kernel-port-tool. Files changed, and what changed them:

  • .github/workflows/rust.yaml — job permissions

Fixed by this PR:

  • MEDIUM excessive-permissions (zizmor) — .github/workflows/rust.yaml:1
  • MEDIUM excessive-permissions (zizmor) — .github/workflows/rust.yaml:15
  • MEDIUM excessive-permissions (zizmor) — .github/workflows/rust.yaml:35
  • MEDIUM excessive-permissions (zizmor) — .github/workflows/rust.yaml:64

This does not fix everything. 3 further finding(s) (3 critical) need a decision this bot should not make for you. They are in the security channel with their locations — deliberately not repeated here, since this repository may be public and they are not fixed yet.

Permissions

.github/workflows/rust.yaml

job granted why
fmt contents: read Only actions/checkout plus cargo fmt checks, so read access to the repository contents is all that is needed.
clippy contents: read actions/checkout drives contents: read; actions/cache and cargo clippy use no token permissions.
test contents: read actions/checkout drives contents: read; actions/cache and cargo test require no additional scopes.

Anything not listed above keeps the permissions it had. To measure a job this could not read, add GitHubSecurityLab/actions-permissions/monitor to it and run the workflow — it reports the minimum the run actually used.

Pinning changes come from pinact and are mechanical. Any other change was generated by Claude — read it before merging.

@paulinebm
paulinebm merged commit a0875ff into kernel-port-tool Sep 23, 2026
27 of 29 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant