Skip to content

pull_request_target is not secure #829

@jeffmaury

Description

@jeffmaury

Would allow someone to submit a PR that dumps all secrets in the run log

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/infrainternal and infrastructure related issues

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions