Skip to content

[pull] master from rollup:master#95

Merged
pull[bot] merged 1 commit intoLeeeeeeM:masterfrom
rollup:master
Jan 29, 2026
Merged

[pull] master from rollup:master#95
pull[bot] merged 1 commit intoLeeeeeeM:masterfrom
rollup:master

Conversation

@pull
Copy link
Copy Markdown

@pull pull bot commented Jan 29, 2026

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

While our pull_request_target flows can only be triggered by adding a label,
there is a short time window where a user could push another commit to the
target. If we do not check out the sha referenced in the Github action but the
ref, then this ref would point to the newly pushed commit, allowing to inject
code to steal credentials.
@pull pull bot locked and limited conversation to collaborators Jan 29, 2026
@pull pull bot added the ⤵️ pull label Jan 29, 2026
@pull pull bot merged commit c79e6c2 into LeeeeeeM:master Jan 29, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant