Hi all,
Please replace insecure usage of pull_request_target. Here is at least one instance:
|
pull_request_target: # requiring access to base repo |
We have pull_request_target guidance and suggested alternatives on the OSDO site at go/github-pull-request-target.
I have limited pull requests to internal QC members only for the time being until this is addressed. Reach out to go/ossops if you have questions or concerns.
Thanks,
Sandhya
Hi all,
Please replace insecure usage of pull_request_target. Here is at least one instance:
meta-ar/.github/workflows/pre_merge_build.yml
Line 6 in fa00a12
We have pull_request_target guidance and suggested alternatives on the OSDO site at go/github-pull-request-target.
I have limited pull requests to internal QC members only for the time being until this is addressed. Reach out to go/ossops if you have questions or concerns.
Thanks,
Sandhya