Re: Verify Change Log action failing

Alan Woodward <[email protected]> Sat, 4 Jul 2026 13:04:01 +0100
Newsgroups gmane.comp.jakarta.lucene.devel
Message-ID <[email protected]>
--Apple-Mail=_9FFEB16A-8B05-4472-B4E9-20EA8886976F
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

Thanks Jan, that looks very helpful.  All fine to wait until after the =
holidays are done.  Enjoy your 4th July beers Robert :)

> On 3 Jul 2026, at 23:35, Jan H=C3=B8ydahl <[email protected]> =
wrote:
>=20
> See Solr's renovate-changelog-* workflows=C2=A0 =
<https://github.com/apache/solr/tree/main/.github/workflows>which safely =
write to a fork's PR branch. We recently converted it from a single =
pull_request_target workflow to this two-stage approach to avoid the =
security risk.
>=20
> Jan
>=20
>> 3. juli 2026 kl. 14:20 skrev Robert Muir <[email protected]>:
>>=20
>> I was worried this would find something when upgrading to
>> actions/checkout version. I'd like to change this workflow to not =
have
>> the security risk, but its a holiday here. Can it wait?
>>=20
>> On Fri, Jul 3, 2026 at 4:08=E2=80=AFAM Alan Woodward =
<[email protected]> wrote:
>>>=20
>>> Hi all,
>>>=20
>>> Our Verify Change Log action in GitHub is failing on every PR now =
with a permissions error:
>>>=20
>>> "Error: Refusing to check out fork pull request code from a =
'pull_request_target' workflow. This workflow runs with the base =
repository's GITHUB_TOKEN, secrets, default-branch cache scope, and =
runner access. Fetching and executing a fork's code in that trusted =
context commonly leads to "pwn request" vulnerabilities. To opt in, =
review the risks at https://gh.io/securely-using-pull_request_target and =
set 'allow-unsafe-pr-checkout: true' on the actions/checkout step.=E2=80=9D=

>>>=20
>>> I don=E2=80=99t know enough about how actions work to know if =
changing `allow-unsafe-pr-checkout` is the right solution here, or if we =
need to change the access for this action somehow?
>>>=20
>>> - Alan
>>> =
---------------------------------------------------------------------
>>> To unsubscribe, e-mail: [email protected]
>>> For additional commands, e-mail: [email protected]
>>>=20
>>=20
>> ---------------------------------------------------------------------
>> To unsubscribe, e-mail: [email protected]
>> For additional commands, e-mail: [email protected]
>>=20
>=20


--Apple-Mail=_9FFEB16A-8B05-4472-B4E9-20EA8886976F
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;" =
class=3D"">Thanks Jan, that looks very helpful. &nbsp;All fine to wait =
until after the holidays are done. &nbsp;Enjoy your 4th July beers =
Robert :)<br class=3D""><div><br class=3D""><blockquote type=3D"cite" =
class=3D""><div class=3D"">On 3 Jul 2026, at 23:35, Jan H=C3=B8ydahl =
&lt;<a href=3D"mailto:[email protected]" =
class=3D"">[email protected]</a>&gt; wrote:</div><br =
class=3D"Apple-interchange-newline"><div class=3D""><meta =
http-equiv=3D"content-type" content=3D"text/html; charset=3Dutf-8" =
class=3D""><div style=3D"overflow-wrap: break-word; -webkit-nbsp-mode: =
space; line-break: after-white-space;" class=3D"">See Solr's&nbsp;<a =
href=3D"https://github.com/apache/solr/tree/main/.github/workflows" =
class=3D"">renovate-changelog-* workflows&nbsp;</a>which safely write to =
a fork's PR branch. We recently converted it from a single =
pull_request_target workflow to this two-stage approach to avoid the =
security risk.<div class=3D""><br class=3D""></div><div class=3D"">Jan<br =
class=3D""><div class=3D""><div class=3D""><br class=3D""><blockquote =
type=3D"cite" class=3D""><div class=3D"">3. juli 2026 kl. 14:20 skrev =
Robert Muir &lt;<a href=3D"mailto:[email protected]" =
class=3D"">[email protected]</a>&gt;:</div><br =
class=3D"Apple-interchange-newline"><div class=3D""><div class=3D"">I =
was worried this would find something when upgrading to<br =
class=3D"">actions/checkout version. I'd like to change this workflow to =
not have<br class=3D"">the security risk, but its a holiday here. Can it =
wait?<br class=3D""><br class=3D"">On Fri, Jul 3, 2026 at 4:08=E2=80=AFAM =
Alan Woodward &lt;<a href=3D"mailto:[email protected]" =
class=3D"">[email protected]</a>&gt; wrote:<br class=3D""><blockquote =
type=3D"cite" class=3D""><br class=3D"">Hi all,<br class=3D""><br =
class=3D"">Our Verify Change Log action in GitHub is failing on every PR =
now with a permissions error:<br class=3D""><br class=3D"">"Error: =
Refusing to check out fork pull request code from a =
'pull_request_target' workflow. This workflow runs with the base =
repository's GITHUB_TOKEN, secrets, default-branch cache scope, and =
runner access. Fetching and executing a fork's code in that trusted =
context commonly leads to "pwn request" vulnerabilities. To opt in, =
review the risks at <a =
href=3D"https://gh.io/securely-using-pull_request_target" =
class=3D"">https://gh.io/securely-using-pull_request_target</a> and set =
'allow-unsafe-pr-checkout: true' on the actions/checkout step.=E2=80=9D<br=
 class=3D""><br class=3D"">I don=E2=80=99t know enough about how actions =
work to know if changing `allow-unsafe-pr-checkout` is the right =
solution here, or if we need to change the access for this action =
somehow?<br class=3D""><br class=3D"">- Alan<br =
class=3D"">---------------------------------------------------------------=
------<br class=3D"">To unsubscribe, <a =
href=3D"mailto:[email protected]" class=3D"">e-mail: =
[email protected]</a><br class=3D"">For additional =
commands, <a href=3D"mailto:[email protected]" class=3D"">e-mail:=
 [email protected]</a><br class=3D""><br =
class=3D""></blockquote><br =
class=3D"">---------------------------------------------------------------=
------<br class=3D"">To unsubscribe, <a =
href=3D"mailto:[email protected]" class=3D"">e-mail: =
[email protected]</a><br class=3D"">For additional =
commands, <a href=3D"mailto:[email protected]" class=3D"">e-mail:=
 [email protected]</a><br class=3D""><br =
class=3D""></div></div></blockquote></div><br =
class=3D""></div></div></div></div></blockquote></div><br =
class=3D""></body></html>=

--Apple-Mail=_9FFEB16A-8B05-4472-B4E9-20EA8886976F--