Skip to content

Conversation

@ishymko
Copy link
Member

@ishymko ishymko commented Dec 17, 2025

Description

Original approach from #262 isn't going to work for PRs from forks, as such actions can't have write access to the upstream repo by default and granting this access is not secure.

Following the approach with a dedicated workflow_run triggered workflow which is executed in a secure context.

Reference: https://securitylab.github.com/resources/github-actions-preventing-pwn-requests/.

Tested in a fork: ishymko#2.

Re #192

@gemini-code-assist
Copy link
Contributor

Note

Gemini is unable to generate a summary for this pull request due to the file types involved not being currently supported.

@ishymko ishymko force-pushed the ishymko/fix-coverage-comment branch from 069e0bd to 717ca00 Compare December 17, 2025 10:06
@ishymko ishymko changed the title ci: fix coverage comment ci: fix coverage comment workflow Dec 17, 2025
@ishymko ishymko force-pushed the ishymko/fix-coverage-comment branch from 717ca00 to ae54838 Compare December 17, 2025 10:10
@ishymko ishymko marked this pull request as ready for review December 17, 2025 10:11
@ishymko ishymko requested a review from a team as a code owner December 17, 2025 10:11
@ishymko ishymko merged commit cda0f56 into main Dec 17, 2025
15 checks passed
@ishymko ishymko deleted the ishymko/fix-coverage-comment branch December 17, 2025 10:26
@ishymko ishymko mentioned this pull request Dec 17, 2025
4 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants