Repository navigation
ci: build on GitHub runners, dual-arch, via EduIDE/.github@v1 #125
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file was deleted.
Oops, something went wrong.
This file was deleted.
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🩺 Stability & Availability | 🟠 Major | 🏗️ Heavy lift
🔎 Supported by static analysis
🏁 Script executed:
Repository: EduIDE/EduIDE-Cloud
Length of output: 2273
🏁 Script executed:
Repository: EduIDE/EduIDE-Cloud
Length of output: 271
🌐 Web query:
GitHub Actions pull_request fork Dependabot GITHUB_TOKEN read-only permissions reusable workflow cannot elevate permissions💡 Result:
GitHub Actions workflows triggered by pull requests from forks—including those opened by Dependabot—are intentionally restricted to a read-only GITHUB_TOKEN and have no access to secrets by design [1][2][3][4]. This is a security feature to prevent untrusted code in a pull request from accessing sensitive environment secrets or gaining unauthorized write access to the repository [5][6][4]. These restrictions apply regardless of any permissions explicitly defined in your workflow file [7][8]. Because this behavior is enforced by the GitHub platform at the event-trigger level, a reusable workflow cannot "elevate" or override these default read-only permissions when the trigger is a pull request from a fork [3][6][4]. To perform tasks that require write permissions or secrets for fork-based pull requests, you must use alternative, secure patterns: 1. Workflow Run Trigger: Use a two-stage process. The first workflow (triggered by pull_request) performs untrusted tasks (like building or testing) and produces artifacts. A second workflow, triggered by workflow_run, executes in the base repository's context with access to secrets and a read-write GITHUB_TOKEN to perform the privileged operations (such as commenting or labeling) [3][4]. 2. pull_request_target Trigger: This trigger runs the workflow from the base repository's default branch, allowing access to secrets and a write-capable token [5][4]. IMPORTANT: This is a high-risk approach [3][4]. You must never check out or execute code from the fork (e.g., using actions/checkout without careful configuration) when using this trigger, as doing so would allow malicious code to hijack the elevated permissions [5][6][4]. 3. Dependabot-Specific Secrets: If your workflow is specifically for Dependabot, note that Dependabot-triggered workflows have access to Dependabot-specific secrets [1][2]. If you need standard repository secrets, ensure they are also defined as Dependabot secrets [1]. In summary, do not attempt to bypass these restrictions in a fork-based pull_request workflow, as the platform will always enforce the read-only limitation [7][8]. Instead, decouple your automation into trusted and untrusted components [3][4].
Citations:
🏁 Script executed:
Repository: EduIDE/EduIDE-Cloud
Length of output: 9332
🏁 Script executed:
Repository: EduIDE/EduIDE-Cloud
Length of output: 1568
Route untrusted pull requests to a build-only workflow.
Fork and Dependabot pull requests receive read-only
GITHUB_TOKENpermissions. The called workflow declarespackages: writebut unconditionally pushes architecture digests and the manifest. These jobs can fail during publication instead of validating the pull request.🤖 Prompt for AI Agents