Syed Muhammad Dawoud Sheraz Ali
01/22/2025, 6:00 PMJoshua Ellis
01/23/2025, 12:04 AMpull_request_target
would get around that, but you can't really adjust it to "just" have access to one secret. So a blanket pull_request_target
trigger is usually not an option, unless you add additional review safeguards.
I highly recommend you read this GitHub blog on the topic: https://securitylab.github.com/resources/github-actions-preventing-pwn-requests/Syed Muhammad Dawoud Sheraz Ali
01/23/2025, 10:50 AM