backport allow-unsafe-pr-checkout to v4 (#2502)
Build and Test / build (push) Failing after 8m28s
Build and Test / test-proxy (push) Failing after 8s
Build and Test / test-bypass-proxy (push) Failing after 41s
Build and Test / test-git-container (push) Failing after 5s
Build and Test / test-output (push) Successful in 9s
Build and Test / test (ubuntu-latest) (push) Failing after 7m44s
Build and Test / test (macos-latest) (push) Has been cancelled
Build and Test / test (windows-latest) (push) Has been cancelled
Build and Test / build (push) Failing after 8m28s
Build and Test / test-proxy (push) Failing after 8s
Build and Test / test-bypass-proxy (push) Failing after 41s
Build and Test / test-git-container (push) Failing after 5s
Build and Test / test-output (push) Successful in 9s
Build and Test / test (ubuntu-latest) (push) Failing after 7m44s
Build and Test / test (macos-latest) (push) Has been cancelled
Build and Test / test (windows-latest) (push) Has been cancelled
* block checking out fork pr for pull_request_target and workflow_run (#2454) * block checking out fork pr for some events * address copilot and reviewer feedback * run prettier formatting * build * update urls * update readme * update description and url again * edit url one more time * update error wording (#2467)
This commit is contained in:
@@ -98,6 +98,15 @@ inputs:
|
||||
github-server-url:
|
||||
description: The base URL for the GitHub instance that you are trying to clone from, will use environment defaults to fetch from the same instance that the workflow is running from unless specified. Example URLs are https://github.com or https://my-ghes-server.example.com
|
||||
required: false
|
||||
allow-unsafe-pr-checkout:
|
||||
description: >
|
||||
Required to check out fork pull request code from a workflow triggered by
|
||||
`pull_request_target` or `workflow_run`. These workflows run with the
|
||||
base repository's GITHUB_TOKEN, secrets, default-branch cache scope, and
|
||||
runner access; fetching and executing a fork's code in that trusted
|
||||
context commonly leads to "pwn request" vulnerabilities. Set to `true`
|
||||
only after reviewing the risks at https://gh.io/securely-using-pull_request_target.
|
||||
default: false
|
||||
outputs:
|
||||
ref:
|
||||
description: 'The branch, tag or SHA that was checked out'
|
||||
|
||||
Reference in New Issue
Block a user