[llvm] workflows/release-doxygen: Add some security checks and input validation (PR #196769)
Tom Stellard via llvm-commits
llvm-commits at lists.llvm.org
Sat May 9 16:23:15 PDT 2026
https://github.com/tstellar created https://github.com/llvm/llvm-project/pull/196769
We now ensure the job was started by a release manager before granting the contents: write permissions and we also validate the input to ensure it is a proper release string and not something malicious.
>From 3c1fa3606278523f3f20b2425a1b1d0e97a33683 Mon Sep 17 00:00:00 2001
From: Tom Stellard <tstellar at redhat.com>
Date: Sat, 9 May 2026 16:20:12 -0700
Subject: [PATCH] workflows/release-doxygen: Add some security checks and input
validation
We now ensure the job was started by a release manager before granting
the contents: write permissions and we also validate the input to ensure
it is a proper release string and not something malicious.
---
.github/workflows/release-doxygen.yml | 32 +++++++++++++++++++
.../validate-release-version/action.yml | 15 +++++++++
2 files changed, 47 insertions(+)
create mode 100644 .github/workflows/validate-release-version/action.yml
diff --git a/.github/workflows/release-doxygen.yml b/.github/workflows/release-doxygen.yml
index 246d7a6304095..5ce776262799d 100644
--- a/.github/workflows/release-doxygen.yml
+++ b/.github/workflows/release-doxygen.yml
@@ -34,6 +34,36 @@ on:
required: true
jobs:
+ # This job checks permissions and validates inputs to prevent potential
+ # malicious actions. Since the release-doxygen job has contents: write
+ # permissions we need to be extract care about who can run the job and
+ # what inputs can be provided.
+ release-doxygen-validate-input:
+ name: Release Doxygen Validate Input
+ runs-on: ubuntu-24.04
+ environment:
+ name: release
+ deployment: false
+ permissions:
+ contents: read
+ steps:
+ - uses: actions/checkout at de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ with:
+ persist-credentials: false
+ sparse-checkout: |
+ .github/workflows/
+
+ - name: Check Permissions
+ uses: ./.github/workflows/require-release-manager
+ with:
+ LLVM_TOKEN_GENERATOR_CLIENT_ID: ${{ secrets.LLVM_TOKEN_GENERATOR_CLIENT_ID }}
+ LLVM_TOKEN_GENERATOR_PRIVATE_KEY: ${{ secrets.LLVM_TOKEN_GENERATOR_PRIVATE_KEY }}
+
+ - name: Validate Input
+ ./.github/workflows/validate-release-version
+ with:
+ release-version: ${{ inputs.release-version }}
+
release-doxygen:
name: Build and Upload Release Doxygen
runs-on: ubuntu-24.04
@@ -42,6 +72,8 @@ jobs:
deployment: false
permissions:
contents: write
+ needs:
+ - release-doxygen-validate-input
env:
upload: ${{ inputs.upload && !contains(inputs.release-version, 'rc') }}
steps:
diff --git a/.github/workflows/validate-release-version/action.yml b/.github/workflows/validate-release-version/action.yml
new file mode 100644
index 0000000000000..9ed99d2c18c86
--- /dev/null
+++ b/.github/workflows/validate-release-version/action.yml
@@ -0,0 +1,15 @@
+name: Validate Release String
+description: >-
+ This checks to make sure that the given release-version string is well formed.
+inputs:
+ release-version:
+ required: true
+
+runs:
+ using: "composite"
+ steps:
+ - env:
+ RELEASE_VERSON: ${{ inputs.release-version }}
+
+ run: |
+ echo $RELEASE_VERSION | grep -e '^[0-9]\+\.[0-9]\+\.[0-9]\+\(-rc[0-9]\+\)\?$'
More information about the llvm-commits
mailing list