Skip to content

[#9889] improvement(build): Use safer implementation for cherry-pick workflow#9890

Merged
jerryshao merged 1 commit intoapache:mainfrom
qqqttt123:ISSUE-9889
Feb 5, 2026
Merged

[#9889] improvement(build): Use safer implementation for cherry-pick workflow#9890
jerryshao merged 1 commit intoapache:mainfrom
qqqttt123:ISSUE-9889

Conversation

@roryqi
Copy link
Contributor

@roryqi roryqi commented Feb 5, 2026

What changes were proposed in this pull request?

Use safer implementation for cherry-pick workflow

Why are the changes needed?

Fix: #9889

Does this PR introduce any user-facing change?

No.

How was this patch tested?

I have tested it in my repo qqqttt123#16

@roryqi roryqi marked this pull request as draft February 5, 2026 06:32
@roryqi roryqi marked this pull request as ready for review February 5, 2026 07:47
@roryqi roryqi requested a review from yuqi1129 February 5, 2026 07:47
@roryqi roryqi self-assigned this Feb 5, 2026
@yuqi1129
Copy link
Contributor

yuqi1129 commented Feb 5, 2026

Are there any documents about what a safer implementation is?

@roryqi
Copy link
Contributor Author

roryqi commented Feb 5, 2026

Are there any documents about what a safer implementation is?

pull_request_target is dangerous, you can see the Apache document https://cwiki.apache.org/confluence/pages/viewpage.action?pageId=321719166#GitHubActionsSecurity-Buildstriggeredwithpull_request_target

@jerryshao jerryshao merged commit 437f46a into apache:main Feb 5, 2026
26 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Improvement] Use safer implementation for cherry-pick workflow

3 participants