mirror of
https://github.com/actions/checkout.git
synced 2026-07-29 22:16:36 +00:00
backport allow-unsafe-pr-checkout to v6 (#2500)
Build and Test / test-git-container (push) Failing after 35s
Build and Test / test-proxy (push) Failing after 36s
Build and Test / test-output (push) Successful in 43s
Build and Test / test-bypass-proxy (push) Failing after 1m2s
Build and Test / test (ubuntu-latest) (push) Failing after 3m18s
Build and Test / build (push) Failing after 13m23s
Build and Test / test (macos-latest) (push) Has been cancelled
Build and Test / test (windows-latest) (push) Has been cancelled
Build and Test / test-git-container (push) Failing after 35s
Build and Test / test-proxy (push) Failing after 36s
Build and Test / test-output (push) Successful in 43s
Build and Test / test-bypass-proxy (push) Failing after 1m2s
Build and Test / test (ubuntu-latest) (push) Failing after 3m18s
Build and Test / build (push) Failing after 13m23s
Build and Test / test (macos-latest) (push) Has been cancelled
Build and Test / test (windows-latest) (push) Has been cancelled
* block checking out fork pr for pull_request_target and workflow_run (#2454) * block checking out fork pr for some events * address copilot and reviewer feedback * run prettier formatting * build * update urls * update readme * update description and url again * edit url one more time * update error wording (#2467)
This commit is contained in:
@@ -98,6 +98,15 @@ inputs:
|
||||
github-server-url:
|
||||
description: The base URL for the GitHub instance that you are trying to clone from, will use environment defaults to fetch from the same instance that the workflow is running from unless specified. Example URLs are https://github.com or https://my-ghes-server.example.com
|
||||
required: false
|
||||
allow-unsafe-pr-checkout:
|
||||
description: >
|
||||
Required to check out fork pull request code from a workflow triggered by
|
||||
`pull_request_target` or `workflow_run`. These workflows run with the
|
||||
base repository's GITHUB_TOKEN, secrets, default-branch cache scope, and
|
||||
runner access; fetching and executing a fork's code in that trusted
|
||||
context commonly leads to "pwn request" vulnerabilities. Set to `true`
|
||||
only after reviewing the risks at https://gh.io/securely-using-pull_request_target.
|
||||
default: false
|
||||
outputs:
|
||||
ref:
|
||||
description: 'The branch, tag or SHA that was checked out'
|
||||
|
||||
Reference in New Issue
Block a user