Skip to content

feat: improve bot-conditions checks#905

Merged
woodruffw merged 7 commits into
mainfrom
ww/bot-conditions-improvements
Jun 6, 2025
Merged

feat: improve bot-conditions checks#905
woodruffw merged 7 commits into
mainfrom
ww/bot-conditions-improvements

Conversation

@woodruffw

@woodruffw woodruffw commented Jun 6, 2025

Copy link
Copy Markdown
Member

WIP.

https://boostsecurity.io/blog/weaponizing-dependabot-pwn-request-at-its-finest made me realize that there were a couple of contexts we weren't checking for properly.

Separately, this also switches bot-conditions to use our context pattern APIs (so that we handle more varieties of contexts, like index-style contexts) and begins the work to ensure we handle numeric actor ID checks as well.

Signed-off-by: William Woodruff <william@yossarian.net>
@woodruffw woodruffw self-assigned this Jun 6, 2025
@woodruffw woodruffw added the enhancement New feature or request label Jun 6, 2025
woodruffw added 6 commits June 6, 2025 16:40
Signed-off-by: William Woodruff <william@yossarian.net>
Signed-off-by: William Woodruff <william@yossarian.net>
Signed-off-by: William Woodruff <william@yossarian.net>
Signed-off-by: William Woodruff <william@yossarian.net>
Signed-off-by: William Woodruff <william@yossarian.net>
Signed-off-by: William Woodruff <william@yossarian.net>
@woodruffw woodruffw merged commit ad7b6d0 into main Jun 6, 2025
8 checks passed
@woodruffw woodruffw deleted the ww/bot-conditions-improvements branch June 6, 2025 21:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant