New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix(dp): Fix typo in domain-proxy Makefile #13019
Conversation
Thanks for opening a PR! 💯
Howto
More infoPlease take a moment to read through the Magma project's
If this is your first Magma PR, also consider reading
|
1ae6063
to
ceb477d
Compare
Signed-off-by: Tomasz Gromowski <tomasz@freedomfi.com>
@magma/approvers-ci |
@@ -6,7 +6,7 @@ on: # yamllint disable-line rule:truthy | |||
branches: | |||
- master | |||
- 'v1.*' | |||
pull_request_target: | |||
pull_request: |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
this reverts the change suggested in #12855 (comment). Can you elaborate why this was done? I think @Neudrino had some reason for his suggestion
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The suggestion was to use the pull_request_target
trigger action to make secrets available. We took the advice without actually verifying the validity of the suggestion.
pull_request_target
is documented as follows:
This event runs in the context of the base of the pull request, rather than in the context of the merge commit, as the pull_request event does. This prevents execution of unsafe code from the head of the pull request that could alter your repository or steal any secrets you use in your workflow. This event allows your workflow to do things like label or comment on pull requests from forks. Avoid using this event if you need to build or run code from the pull request.
We are building code from the pull request, as that is the whole idea of running integration tests.
Secondly, the only secret we use is the GITHUB_TOKEN
which is an exception to availability of secrets in PRs from forks:
With the exception of GITHUB_TOKEN, secrets are not passed to the runner when a workflow is triggered from a forked repository.
Now, since we have introduced the pull_request_target
, the CI was run from the base of the PRs, rather from the head of the PR branch, and that hid the mistake in the Makefile
.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The changes look good, just the pull_request_target
-> pull_request
change is not explained
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
Signed-off-by: Tomasz Gromowski <tomasz@freedomfi.com>
Signed-off-by: Tomasz Gromowski tomasz@freedomfi.com
Summary
Fix typo iuntroduced by #12999
Test Plan
Additional Information