You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Sorry if there is a mitigation in here I've missed, wanted to validate if this was possible.
Is it possible, for example, to edit the privileged-requester.yaml file in the PR where I make my changes so that it includes my user as a privileged requestor?
In a similar issue to the one @nobe4 mentioned 👇 , could I set commitVerification to false in the branch to allow impersonation and then push as the bot user with unsigned commits?
I think these would be mitigated by reading the configuration from the default branch rather than from the PR branch but I'm not sure how to work that with