Skip to content

ci: Resolve GitHub Actions security and fix Zizmor findings for TFT - #353

Merged
vkarampudi merged 1 commit into
tensorflow:masterfrom
vkarampudi:fix-zizmor-security
Aug 14, 2026
Merged

ci: Resolve GitHub Actions security and fix Zizmor findings for TFT#353
vkarampudi merged 1 commit into
tensorflow:masterfrom
vkarampudi:fix-zizmor-security

Conversation

@vkarampudi

Copy link
Copy Markdown
Contributor

Summary of Changes

This PR addresses all security findings and warnings reported by the centralized Zizmor security scanner (google-gh-automation / Zizmor) across the repository's GitHub Actions workflows and documentation build configuration.

Key Improvements

  1. Least-Privilege Permissions (excessive-permissions & artipacked):

    • Added global permissions: contents: read to all workflows (ci-lint.yml, ci-test.yml, docs.yml, wheels.yml).
    • Added persist-credentials: false across all actions/checkout steps to avoid persisting GitHub tokens into build runners.
    • Scoped id-token: write strictly to the upload_to_pypi job in wheels.yml.
    • Converted docs.yml to pure read-only doc syntax validation (mkdocs build), eliminating unnecessary contents: write tokens on PRs.
  2. Full Action SHA Pinning (unpinned-uses & known-vulnerable-actions):

    • Pinned all GitHub Actions to exact, immutable commit SHAs with version comments:
      • actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 (# v4.2.2)
      • actions/setup-python@42375524e23c412d93fb67b49958b491fce71c38 (# v5.4.0)
      • actions/upload-artifact@4cec3d8aa04e39d1a68397de0c4cd6fb9dce8ec1 (# v4.6.1)
      • actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 (# v4.1.8)
      • pre-commit/action@2c7b3805fd2a0fd8c1884dcaebf91fc102a13ecd (# v3.0.1)
      • pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 (# release/v1) with # zizmor: ignore[use-trusted-publishing]
  3. Documentation Build Compatibility (mkdocs.yml):

    • Moved inventories: directly under mkdocstrings: to maintain compatibility with modern mkdocstrings-python releases.

Verification

  • Validated locally with zizmor (v1.25.2 & v1.29.0): 0 findings (Clean pass, exit code 0).

@vkarampudi vkarampudi changed the title ci:Resolve GitHub Actions security and fix Zizmor findings for TFT ci: Resolve GitHub Actions security and fix Zizmor findings for TFT Aug 13, 2026

@rwitcher rwitcher left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@vkarampudi
vkarampudi merged commit deefef1 into tensorflow:master Aug 14, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants