Skip to content

Commit 13c7528

Browse files
kirkrodriguesdavidlion
authored andcommitted
ci(pr-title-checks): Remove default GH workflow permissions and document risk of pull_request_target workflow trigger. (y-scope#633)
1 parent 42db88c commit 13c7528

File tree

1 file changed

+7
-0
lines changed

1 file changed

+7
-0
lines changed

.github/workflows/clp-pr-title-checks.yaml

+7
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,16 @@ name: "clp-pr-title-checks"
22

33
on:
44
pull_request_target:
5+
# NOTE: Workflows triggered by this event give the workflow access to secrets and grant the
6+
# `GITHUB_TOKEN` read/write repository access by default. So we need to ensure:
7+
# - This workflow doesn't inadvertently check out, build, or execute untrusted code from the
8+
# pull request triggered by this event.
9+
# - Each job has `permissions` set to only those necessary.
510
types: ["edited", "opened", "reopened"]
611
branches: ["main"]
712

13+
permissions: {}
14+
815
concurrency:
916
group: "${{github.workflow}}-${{github.ref}}"
1017

0 commit comments

Comments
 (0)