forked from jgm/lunamark
-
Notifications
You must be signed in to change notification settings - Fork 31
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
GitHub security policy disallows sharing secrets with forks in public repositories [1]. However, we need pull requests to push temporary Docker images to a registry, which requires access to secrets unless we use GitHub Packages. To work around this, this commit switches to the `pull_request_target` event, which works on the repository and commit that the pull request is based on, but manually checks out and uses the code from the pull request. This is a mild security hazard but should be OK, since workflows on pull requests from new contributors need to be approved anyways. [1]: https://securitylab.github.com/research/github-actions-preventing-pwn-requests/
- Loading branch information
Showing
1 changed file
with
24 additions
and
5 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters