Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Finer-grained of workflow runs, between 'anyone but first-time contributors' and 'only committers' #256

Closed
holly-cummins opened this issue Aug 9, 2022 · 0 comments · Fixed by #261

Comments

@holly-cummins
Copy link
Contributor

At the moment GitHub only has two options for which PRs will be automatically run on a repository's actions without a manual approval: everyone but first time contributors, or only contributors.
This means if someone has a trivial PR accepted, they can run malicious PRs. This is non-ideal on git-hosted runners, and a serious concern on self-hosted runners.

Scrolling down to "Public Repository Warning" in https://www.ideasawakened.com/post/radauthenticator-part-4-build-automation-with-delphi-and-github-by-installing-a-self-hosted-runner has a good discussion of the issue.

Requiring manual approval of runs from everyone but committers will be too onerous, but the bot could apply rules to pre-handle all but ambiguous cases.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant