Skip to content

Conversation

@rikkihamano
Copy link

No description provided.

@rikkihamano rikkihamano merged commit d125369 into v2ray:master Jul 21, 2020
@kslr
Copy link
Contributor

kslr commented Jul 21, 2020

内置的github_token没办法对其他仓库修改,原来的token也是有效的,只是邮箱变成了未验证状态.
另外我尝试修改了用户名 56362ce

@rikkihamano
Copy link
Author

内置的github_token没办法对其他仓库修改,原来的token也是有效的,只是邮箱变成了未验证状态.
另外我尝试修改了用户名 56362ce

感谢提醒,我刚刚发现 actions 似乎有安全问题,想请帮忙确认一下

pull_request:
branches: [ master ]

env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}

也就是说任何人都可以 fork 并修改 deploy.sh,然后提 PR,通过 token 对这个仓库做任何事情,是这样的吗

@kslr
Copy link
Contributor

kslr commented Jul 22, 2020

看起来是的,可以把token发送出去,所以应该把pull关掉

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants