fix(ci): harden test262 PR workflow security#5159
Merged
jedel1043 merged 1 commit intoboa-dev:mainfrom Mar 19, 2026
Merged
Conversation
Test262 conformance changes
Tested main commit: |
954fff6 to
d17cfcc
Compare
d17cfcc to
1dd2319
Compare
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #5159 +/- ##
===========================================
+ Coverage 47.24% 59.56% +12.31%
===========================================
Files 476 580 +104
Lines 46892 63236 +16344
===========================================
+ Hits 22154 37665 +15511
- Misses 24738 25571 +833 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #5158.
This replaces the old
test262_pr.ymlflow with a safer two-phase setup:test262.yml: runs underpull_requestwith minimal permissions and executes the test262 suite on PR codetest262_comment.yml: runs underworkflow_runin the base repository context and updates the PR comment from an uploaded artifactMain changes:
pull_request_targetbody-pathfor comment updatesThis preserves the reporting behavior while avoiding execution of PR code in a privileged workflow context.