Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

BUG: don't warn on secrets in pull_request #1863

Closed
laurentsimon opened this issue Apr 25, 2022 · 0 comments · Fixed by #1864
Closed

BUG: don't warn on secrets in pull_request #1863

laurentsimon opened this issue Apr 25, 2022 · 0 comments · Fixed by #1864
Assignees
Labels
kind/bug Something isn't working

Comments

@laurentsimon
Copy link
Contributor

https://securitylab.github.com/research/github-actions-preventing-pwn-requests/:

Due to the dangers inherent to automatic processing of PRs, GitHub’s standard pull_request workflow trigger by default prevents write permissions and secrets access to the target repository.

We're looking for secrets in pull_request triggers, but should not.

Thanks @jeffmendoza and @sethvargo for flagging

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/bug Something isn't working
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant