2 parents 7bcb7e4 + 7adbce0 commit d40017fCopy full SHA for d40017f
1 file changed
.github/workflows/auto-dependabot.yaml
@@ -1,7 +1,15 @@
1
name: Auto-merge Dependabot PR
2
3
on:
4
- pull_request:
+ # XXX: !!! SECURITY WARNING !!!
5
+ # pull_request_target has write access to the repo, and can read secrets. We
6
+ # need to audit any external actions executed in this workflow and make sure no
7
+ # checked out code is run (not even installing dependencies, as installing
8
+ # dependencies usually can execute pre/post-install scripts). We should also
9
+ # only use hashes to pick the action to execute (instead of tags or branches).
10
+ # For more details read:
11
+ # https://securitylab.github.com/research/github-actions-preventing-pwn-requests/
12
+ pull_request_target:
13
14
permissions:
15
contents: read
0 commit comments