Skip to content

ci: remove pull_request_target, sanitise github.ref_name - #1567

Merged
MarcoGorelli merged 1 commit into
narwhals-dev:mainfrom
MarcoGorelli:remove-pull-request-target
Dec 12, 2024
Merged

ci: remove pull_request_target, sanitise github.ref_name#1567
MarcoGorelli merged 1 commit into
narwhals-dev:mainfrom
MarcoGorelli:remove-pull-request-target

Conversation

@MarcoGorelli

@MarcoGorelli MarcoGorelli commented Dec 12, 2024

Copy link
Copy Markdown
Member

pull_request_target is flagged as unsafe by zizmor

in wake of https://blog.pypi.org/posts/2024-12-11-ultralytics-attack-analysis/, i think it might be best to just remove it

we'll just have to remember to set labels before merging, but i think we can get into that habit - else we just fixup the release notes before publishing, no big deal

What type of PR is this? (check all applicable)

  • 💾 Refactor
  • ✨ Feature
  • 🐛 Bug Fix
  • 🔧 Optimization
  • 📝 Documentation
  • ✅ Test
  • 🐳 Other

Related issues

  • Related issue #<issue number>
  • Closes #<issue number>

Checklist

  • Code follows style guide (ruff)
  • Tests added
  • Documented the changes

If you have comments or can explain your changes, please do so below

@MarcoGorelli
MarcoGorelli marked this pull request as ready for review December 12, 2024 10:43
@MarcoGorelli
MarcoGorelli merged commit 4039440 into narwhals-dev:main Dec 12, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant