[llvm] workflows/release-doxygen: Add some security checks and input validation (PR #196769)

Tom Stellard via llvm-commits llvm-commits at lists.llvm.org
Sat May 9 16:23:15 PDT 2026


https://github.com/tstellar created https://github.com/llvm/llvm-project/pull/196769

We now ensure the job was started by a release manager before granting the contents: write permissions and we also validate the input to ensure it is a proper release string and not something malicious.

>From 3c1fa3606278523f3f20b2425a1b1d0e97a33683 Mon Sep 17 00:00:00 2001
From: Tom Stellard <tstellar at redhat.com>
Date: Sat, 9 May 2026 16:20:12 -0700
Subject: [PATCH] workflows/release-doxygen: Add some security checks and input
 validation

We now ensure the job was started by a release manager before granting
the contents: write permissions and we also validate the input to ensure
it is a proper release string and not something malicious.
---
 .github/workflows/release-doxygen.yml         | 32 +++++++++++++++++++
 .../validate-release-version/action.yml       | 15 +++++++++
 2 files changed, 47 insertions(+)
 create mode 100644 .github/workflows/validate-release-version/action.yml

diff --git a/.github/workflows/release-doxygen.yml b/.github/workflows/release-doxygen.yml
index 246d7a6304095..5ce776262799d 100644
--- a/.github/workflows/release-doxygen.yml
+++ b/.github/workflows/release-doxygen.yml
@@ -34,6 +34,36 @@ on:
         required: true
 
 jobs:
+  # This job checks permissions and validates inputs to prevent potential
+  # malicious actions.  Since the release-doxygen job has contents: write
+  # permissions we need to be extract care about who can run the job and
+  # what inputs can be provided.
+  release-doxygen-validate-input:
+    name: Release Doxygen Validate Input
+    runs-on: ubuntu-24.04
+    environment:
+      name: release
+      deployment: false
+    permissions:
+      contents: read
+    steps:
+      - uses: actions/checkout at de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+        with:
+          persist-credentials: false
+          sparse-checkout: |
+            .github/workflows/
+
+      - name: Check Permissions
+        uses: ./.github/workflows/require-release-manager
+        with:
+          LLVM_TOKEN_GENERATOR_CLIENT_ID: ${{ secrets.LLVM_TOKEN_GENERATOR_CLIENT_ID }}
+          LLVM_TOKEN_GENERATOR_PRIVATE_KEY: ${{ secrets.LLVM_TOKEN_GENERATOR_PRIVATE_KEY }}
+
+      - name: Validate Input
+        ./.github/workflows/validate-release-version
+        with:
+          release-version: ${{ inputs.release-version }}
+
   release-doxygen:
     name: Build and Upload Release Doxygen
     runs-on: ubuntu-24.04
@@ -42,6 +72,8 @@ jobs:
       deployment: false
     permissions:
       contents: write
+    needs:
+      - release-doxygen-validate-input
     env:
       upload: ${{ inputs.upload && !contains(inputs.release-version, 'rc') }}
     steps:
diff --git a/.github/workflows/validate-release-version/action.yml b/.github/workflows/validate-release-version/action.yml
new file mode 100644
index 0000000000000..9ed99d2c18c86
--- /dev/null
+++ b/.github/workflows/validate-release-version/action.yml
@@ -0,0 +1,15 @@
+name: Validate Release String
+description: >-
+  This checks to make sure that the given release-version string is well formed.
+inputs:
+  release-version:
+    required: true
+
+runs:
+  using: "composite"
+  steps:
+    - env:
+      RELEASE_VERSON: ${{ inputs.release-version }}
+
+      run: |
+        echo $RELEASE_VERSION | grep -e '^[0-9]\+\.[0-9]\+\.[0-9]\+\(-rc[0-9]\+\)\?$'



More information about the llvm-commits mailing list