Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SOFA PRs may be able to be abused by non-approved authors #103

Open
erikng opened this issue Jul 20, 2024 · 1 comment
Open

SOFA PRs may be able to be abused by non-approved authors #103

erikng opened this issue Jul 20, 2024 · 1 comment
Labels
help wanted Extra attention is needed invalid This doesn't seem right

Comments

@erikng
Copy link
Member

erikng commented Jul 20, 2024

The current github action has no safety when running on branches or PRs. I rogue PR may be able to abuse this action and steal our credentials.

@erikng
Copy link
Member Author

erikng commented Jul 22, 2024

so it turns out this may not be an issue

https://github.com/orgs/community/discussions/26374

and it's not even possible to fix when using the cron option. We just need to be careful if we ever add other github actions.

@erikng erikng added help wanted Extra attention is needed invalid This doesn't seem right labels Jul 22, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
help wanted Extra attention is needed invalid This doesn't seem right
Projects
None yet
Development

No branches or pull requests

1 participant