Skip to content
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 20 additions & 0 deletions .github/workflows/test-pr-workflows.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
name: Test PR Workflows (TEMPORARY - DELETE AFTER TESTING)

on:
pull_request:

Copilot AI Apr 8, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This workflow is triggered on pull_request, but the repo’s main PR workflow uses pull_request_target specifically to support PRs from forks (.github/workflows/pr-workflow.yaml:4-6). With pull_request, GITHUB_TOKEN is read-only on fork PRs, so the test-copyright-check job won’t actually receive the requested pull-requests: write / issues: write permissions and the reusable workflow may fail to comment/update checks. Consider using pull_request_target (with the reusable workflow designed to avoid checking out untrusted code) if you need this to behave like the main PR workflow.

Suggested change
pull_request:
pull_request_target:

Copilot uses AI. Check for mistakes.
types: [opened, edited, reopened, synchronize]
Comment on lines +4 to +5

Copilot AI Apr 8, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This file is labeled as TEMPORARY but is wired to run on every PR event type listed. If it’s only for ad-hoc validation, consider gating it (e.g., workflow_dispatch, branch/actor filtering, or a short-lived test branch) to avoid duplicating checks and increasing Actions noise/cost if merged accidentally.

Suggested change
pull_request:
types: [opened, edited, reopened, synchronize]
workflow_dispatch:

Copilot uses AI. Check for mistakes.

jobs:
test-jira-check:
name: Test JIRA ID Check
uses: marklogic/pr-workflows/.github/workflows/jira-id-check.yml@fix/SECCMP-1797-pwn-request-injection
with:
pr-title: ${{ github.event.pull_request.title }}

test-copyright-check:
name: Test Copyright Check
uses: marklogic/pr-workflows/.github/workflows/copyright-check.yml@fix/SECCMP-1797-pwn-request-injection
Comment on lines +10 to +16

Copilot AI Apr 8, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The reusable workflows are referenced via a mutable branch ref (@fix/SECCMP-1797-pwn-request-injection). For workflow security hardening, pin reusable workflow calls to an immutable ref (a commit SHA or a protected, versioned tag) to avoid supply-chain risk if the branch changes.

Suggested change
uses: marklogic/pr-workflows/.github/workflows/jira-id-check.yml@fix/SECCMP-1797-pwn-request-injection
with:
pr-title: ${{ github.event.pull_request.title }}
test-copyright-check:
name: Test Copyright Check
uses: marklogic/pr-workflows/.github/workflows/copyright-check.yml@fix/SECCMP-1797-pwn-request-injection
uses: marklogic/pr-workflows/.github/workflows/jira-id-check.yml@<FULL_40_CHAR_COMMIT_SHA_FOR_fix/SECCMP-1797-pwn-request-injection>
with:
pr-title: ${{ github.event.pull_request.title }}
test-copyright-check:
name: Test Copyright Check
uses: marklogic/pr-workflows/.github/workflows/copyright-check.yml@<FULL_40_CHAR_COMMIT_SHA_FOR_fix/SECCMP-1797-pwn-request-injection>

Copilot uses AI. Check for mistakes.
permissions:
contents: read
pull-requests: write
issues: write
Loading