Commit ea2e524
authored
Improve sandboxing of
This restricts the action to be no longer able to push content, so it can only comment on PRs or open and close (not merge) them.
This means that even if someone manages to bypass the sandboxing somehow, they can not really exploit this workflow to extract secrets etc.pull_request_target workflow1 parent 8d4bd69 commit ea2e524
1 file changed
+4
-0
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
9 | 9 | | |
10 | 10 | | |
11 | 11 | | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
12 | 16 | | |
13 | 17 | | |
14 | 18 | | |
| |||
0 commit comments