Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[CI] switch from pull_request to pull_request_target for github actions #5658

Open
svrnm opened this issue Nov 21, 2024 · 0 comments
Open

[CI] switch from pull_request to pull_request_target for github actions #5658

svrnm opened this issue Nov 21, 2024 · 0 comments
Labels
CI/infra CI & infrastructure

Comments

@svrnm
Copy link
Member

svrnm commented Nov 21, 2024

We might consider to replace the event target for some of our CI actions from pull_request to pull_request_target, one reason is security (see here), but it also looks like that this may help with a situation where write permissions are not available (e.g. in a PR from an Org to our repo)?

See also Permissions

@svrnm svrnm added the CI/infra CI & infrastructure label Nov 21, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
CI/infra CI & infrastructure
Projects
Status: No status
Development

No branches or pull requests

1 participant