Skip to content

Commit d40017f

Browse files
authored
Use pull_request_target trigger instead of pull_request (#124)
We need this in order to be able to get the secrets.
2 parents 7bcb7e4 + 7adbce0 commit d40017f

1 file changed

Lines changed: 9 additions & 1 deletion

File tree

‎.github/workflows/auto-dependabot.yaml‎

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,15 @@
11
name: Auto-merge Dependabot PR
22

33
on:
4-
pull_request:
4+
# XXX: !!! SECURITY WARNING !!!
5+
# pull_request_target has write access to the repo, and can read secrets. We
6+
# need to audit any external actions executed in this workflow and make sure no
7+
# checked out code is run (not even installing dependencies, as installing
8+
# dependencies usually can execute pre/post-install scripts). We should also
9+
# only use hashes to pick the action to execute (instead of tags or branches).
10+
# For more details read:
11+
# https://securitylab.github.com/research/github-actions-preventing-pwn-requests/
12+
pull_request_target:
513

614
permissions:
715
contents: read

0 commit comments

Comments
 (0)