Skip to content

chore: remove claude.yml workflow file#4031

Merged
Wauplin merged 2 commits intomainfrom
security-fix/-github-workflows-claude-yml-1775131746
Apr 2, 2026
Merged

chore: remove claude.yml workflow file#4031
Wauplin merged 2 commits intomainfrom
security-fix/-github-workflows-claude-yml-1775131746

Conversation

@hf-security-analysis
Copy link
Copy Markdown
Contributor

@hf-security-analysis hf-security-analysis Bot commented Apr 2, 2026

Removes .github/workflows/claude.yml workflow configuration.

We don't use Claude on Github so let's delete it to reduce surface attack.

cc @paulinebm

Closes huggingface/tracking-issues#260


Note

Low Risk
Low risk since this only deletes an unused GitHub Actions workflow; the main impact is loss of the ability to trigger the Claude PR assistant via @claude comments.

Overview
Removes the .github/workflows/claude.yml GitHub Actions workflow that ran anthropics/claude-code-action when issues/PR comments or reviews contained @claude.

This reduces CI/automation surface area by eliminating the associated workflow triggers and permissions.

Written by Cursor Bugbot for commit 07be0e9. This will update automatically on new commits. Configure here.

@hf-security-analysis hf-security-analysis Bot requested a review from paulinebm April 2, 2026 12:09
Copy link
Copy Markdown

@cursor cursor Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 3 potential issues.

Fix All in Cursor

Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Comment thread .github/workflows/claude.yml Outdated
Comment thread .github/workflows/claude.yml Outdated
Comment thread .github/workflows/claude.yml Outdated
@bot-ci-comment
Copy link
Copy Markdown

bot-ci-comment Bot commented Apr 2, 2026

The docs for this PR live here. All of your documentation changes will be reflected on that endpoint. The docs are available until 30 days after the last update.

@Wauplin
Copy link
Copy Markdown
Contributor

Wauplin commented Apr 2, 2026

@paulinebm we actually don't use this github action at all (Cursot bugbot is enough). So another solution to reduce attack surface is to simply delete this workflow file entirely

@Wauplin Wauplin changed the title chore: update claude.yml chore: remove claude.yml workflow file Apr 2, 2026
@Wauplin Wauplin merged commit 657b8b9 into main Apr 2, 2026
10 of 21 checks passed
@Wauplin Wauplin deleted the security-fix/-github-workflows-claude-yml-1775131746 branch April 2, 2026 15:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant