Skip to content

Conversation

@woodruffw
Copy link
Member

See python/cpython#127749 (comment) -- this took a bit of sleuthing, but the pull_request event body's commits field can only ever contain a number, meaning that it isn't itself a source of code injection.

Ref: https://docs.github.com/en/rest/pulls/pulls?apiVersion=2022-11-28#get-a-pull-request

@woodruffw woodruffw added the bugfix Fixes a known bug label Dec 8, 2024
@woodruffw woodruffw self-assigned this Dec 8, 2024
@woodruffw woodruffw enabled auto-merge (squash) December 8, 2024 23:11
@woodruffw woodruffw merged commit 1f45126 into main Dec 8, 2024
19 checks passed
@woodruffw woodruffw deleted the ww/safe-context branch December 8, 2024 23:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugfix Fixes a known bug

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants