Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(CI): Update to pull_request trigger #44930

Closed
wants to merge 1 commit into from
Closed

Conversation

solracsf
Copy link
Member

@solracsf solracsf commented Apr 19, 2024

Summary

Using pull_request_target can expose secrets based on a quirk in how GitHub applies permissions to forks.
See https://docs.github.com/en/actions/using-workflows/events-that-trigger-workflows#pull_request_target

Even if i'm not sure this is a problem here as this Workflow applies to Dependabot, submitting the PR to review :)

Checklist

Signed-off-by: Git'Fellow <12234510+solracsf@users.noreply.github.com>
@solracsf solracsf added the 3. to review Waiting for reviews label Apr 19, 2024
@solracsf solracsf added this to the Nextcloud 30 milestone Apr 19, 2024
@skjnldsv skjnldsv added 2. developing Work in progress stale Ticket or PR with no recent activity and removed 3. to review Waiting for reviews labels Jul 27, 2024
@blizzz blizzz mentioned this pull request Jul 30, 2024
@solracsf solracsf closed this Jul 31, 2024
@skjnldsv skjnldsv removed this from the Nextcloud 30 milestone Aug 14, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
2. developing Work in progress stale Ticket or PR with no recent activity
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants