Re: Verify Change Log action failing
Alan Woodward <[email protected]> Sat, 4 Jul 2026 13:04:01 +0100
| Newsgroups | gmane.comp.jakarta.lucene.devel |
|---|---|
| Message-ID | <[email protected]> |
--Apple-Mail=_9FFEB16A-8B05-4472-B4E9-20EA8886976F Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=utf-8 Thanks Jan, that looks very helpful. All fine to wait until after the = holidays are done. Enjoy your 4th July beers Robert :) > On 3 Jul 2026, at 23:35, Jan H=C3=B8ydahl <[email protected]> = wrote: >=20 > See Solr's renovate-changelog-* workflows=C2=A0 = <https://github.com/apache/solr/tree/main/.github/workflows>which safely = write to a fork's PR branch. We recently converted it from a single = pull_request_target workflow to this two-stage approach to avoid the = security risk. >=20 > Jan >=20 >> 3. juli 2026 kl. 14:20 skrev Robert Muir <[email protected]>: >>=20 >> I was worried this would find something when upgrading to >> actions/checkout version. I'd like to change this workflow to not = have >> the security risk, but its a holiday here. Can it wait? >>=20 >> On Fri, Jul 3, 2026 at 4:08=E2=80=AFAM Alan Woodward = <[email protected]> wrote: >>>=20 >>> Hi all, >>>=20 >>> Our Verify Change Log action in GitHub is failing on every PR now = with a permissions error: >>>=20 >>> "Error: Refusing to check out fork pull request code from a = 'pull_request_target' workflow. This workflow runs with the base = repository's GITHUB_TOKEN, secrets, default-branch cache scope, and = runner access. Fetching and executing a fork's code in that trusted = context commonly leads to "pwn request" vulnerabilities. To opt in, = review the risks at https://gh.io/securely-using-pull_request_target and = set 'allow-unsafe-pr-checkout: true' on the actions/checkout step.=E2=80=9D= >>>=20 >>> I don=E2=80=99t know enough about how actions work to know if = changing `allow-unsafe-pr-checkout` is the right solution here, or if we = need to change the access for this action somehow? >>>=20 >>> - Alan >>> = --------------------------------------------------------------------- >>> To unsubscribe, e-mail: [email protected] >>> For additional commands, e-mail: [email protected] >>>=20 >>=20 >> --------------------------------------------------------------------- >> To unsubscribe, e-mail: [email protected] >> For additional commands, e-mail: [email protected] >>=20 >=20 --Apple-Mail=_9FFEB16A-8B05-4472-B4E9-20EA8886976F Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=utf-8 <html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; = charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; = -webkit-nbsp-mode: space; line-break: after-white-space;" = class=3D"">Thanks Jan, that looks very helpful. All fine to wait = until after the holidays are done. Enjoy your 4th July beers = Robert :)<br class=3D""><div><br class=3D""><blockquote type=3D"cite" = class=3D""><div class=3D"">On 3 Jul 2026, at 23:35, Jan H=C3=B8ydahl = <<a href=3D"mailto:[email protected]" = class=3D"">[email protected]</a>> wrote:</div><br = class=3D"Apple-interchange-newline"><div class=3D""><meta = http-equiv=3D"content-type" content=3D"text/html; charset=3Dutf-8" = class=3D""><div style=3D"overflow-wrap: break-word; -webkit-nbsp-mode: = space; line-break: after-white-space;" class=3D"">See Solr's <a = href=3D"https://github.com/apache/solr/tree/main/.github/workflows" = class=3D"">renovate-changelog-* workflows </a>which safely write to = a fork's PR branch. We recently converted it from a single = pull_request_target workflow to this two-stage approach to avoid the = security risk.<div class=3D""><br class=3D""></div><div class=3D"">Jan<br = class=3D""><div class=3D""><div class=3D""><br class=3D""><blockquote = type=3D"cite" class=3D""><div class=3D"">3. juli 2026 kl. 14:20 skrev = Robert Muir <<a href=3D"mailto:[email protected]" = class=3D"">[email protected]</a>>:</div><br = class=3D"Apple-interchange-newline"><div class=3D""><div class=3D"">I = was worried this would find something when upgrading to<br = class=3D"">actions/checkout version. I'd like to change this workflow to = not have<br class=3D"">the security risk, but its a holiday here. Can it = wait?<br class=3D""><br class=3D"">On Fri, Jul 3, 2026 at 4:08=E2=80=AFAM = Alan Woodward <<a href=3D"mailto:[email protected]" = class=3D"">[email protected]</a>> wrote:<br class=3D""><blockquote = type=3D"cite" class=3D""><br class=3D"">Hi all,<br class=3D""><br = class=3D"">Our Verify Change Log action in GitHub is failing on every PR = now with a permissions error:<br class=3D""><br class=3D"">"Error: = Refusing to check out fork pull request code from a = 'pull_request_target' workflow. This workflow runs with the base = repository's GITHUB_TOKEN, secrets, default-branch cache scope, and = runner access. Fetching and executing a fork's code in that trusted = context commonly leads to "pwn request" vulnerabilities. To opt in, = review the risks at <a = href=3D"https://gh.io/securely-using-pull_request_target" = class=3D"">https://gh.io/securely-using-pull_request_target</a> and set = 'allow-unsafe-pr-checkout: true' on the actions/checkout step.=E2=80=9D<br= class=3D""><br class=3D"">I don=E2=80=99t know enough about how actions = work to know if changing `allow-unsafe-pr-checkout` is the right = solution here, or if we need to change the access for this action = somehow?<br class=3D""><br class=3D"">- Alan<br = class=3D"">---------------------------------------------------------------= ------<br class=3D"">To unsubscribe, <a = href=3D"mailto:[email protected]" class=3D"">e-mail: = [email protected]</a><br class=3D"">For additional = commands, <a href=3D"mailto:[email protected]" class=3D"">e-mail:= [email protected]</a><br class=3D""><br = class=3D""></blockquote><br = class=3D"">---------------------------------------------------------------= ------<br class=3D"">To unsubscribe, <a = href=3D"mailto:[email protected]" class=3D"">e-mail: = [email protected]</a><br class=3D"">For additional = commands, <a href=3D"mailto:[email protected]" class=3D"">e-mail:= [email protected]</a><br class=3D""><br = class=3D""></div></div></blockquote></div><br = class=3D""></div></div></div></div></blockquote></div><br = class=3D""></body></html>= --Apple-Mail=_9FFEB16A-8B05-4472-B4E9-20EA8886976F--