Re: Verify Change Log action failing

Dawid Weiss <[email protected]> Mon, 6 Jul 2026 18:31:56 +0200
Newsgroups gmane.comp.jakarta.lucene.devel
Message-ID <CAM21Rt8g02ofHf8UHJdVu-h0qs5oUKG39VM3nDnCabs5ogNXig@mail.gmail.com>
--000000000000a926cb0655f3d160
Content-Type: text/plain; charset="UTF-8"

> See Solr's renovate-changelog-* workflows
> <https://github.com/apache/solr/tree/main/.github/workflows>which safely
> write to a fork's PR branch. We recently converted it from a single
> pull_request_target workflow to this two-stage approach to avoid the
> security risk.


This is far from trivial though? Requires a separate github account and a
pat token with permissions. I'll just turn off this workflow for now
because it makes life unbearable.

Dawid

--000000000000a926cb0655f3d160
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"ltr"><br></div><div class=3D"gmail_quote gmail=
_quote_container"><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px=
 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">See Sol=
r&#39;s=C2=A0<a href=3D"https://github.com/apache/solr/tree/main/.github/wo=
rkflows" target=3D"_blank">renovate-changelog-* workflows=C2=A0</a>which sa=
fely write to a fork&#39;s PR branch. We recently converted it from a singl=
e pull_request_target workflow to this two-stage approach to avoid the secu=
rity risk.</blockquote><div><br></div><div>This is far from trivial though?=
 Requires a separate github account and a pat token with permissions. I&#39=
;ll just turn off this workflow for now because it makes life unbearable.</=
div><div><br></div><div>Dawid</div></div></div>

--000000000000a926cb0655f3d160--