Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Try out approving workflow runs from public forks #136

Open
sverhoeven opened this issue Apr 26, 2021 · 2 comments
Open

Try out approving workflow runs from public forks #136

sverhoeven opened this issue Apr 26, 2021 · 2 comments

Comments

@sverhoeven
Copy link
Collaborator

In https://github.blog/2021-04-22-github-actions-update-helping-maintainers-combat-bad-actors/ is explained that now first time contributors need approval before the workflows are run. Also see the docs.

This mechanism also greatly reduces the threat of misuse of self hosted runners. As random folks from the Internet can no longer trigger a job to be run on our self hosted runner without approval.

@sverhoeven
Copy link
Collaborator Author

@felipeZ and @JensWehner I think this makes running a self hosted runner on a public repo much more secure. Could you try it out?

@sverhoeven
Copy link
Collaborator Author

See actions/runner#494 for more advanced proposal

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant