Skip to content

Security finding — possible pull_request_target pattern (details on request) #1

Security finding — possible pull_request_target pattern (details on request)

Security finding — possible pull_request_target pattern (details on request) #1

name: Acknowledge New Issue
on:
issues:
types: [opened]
permissions:
issues: write
jobs:
acknowledge:
runs-on: ubuntu-latest
steps:
- name: Comment on issue
uses: actions/github-script@v7
with:
script: |
const creator = context.payload.issue.user.login;
await github.rest.issues.createComment({
owner: context.repo.owner,
repo: context.repo.repo,
issue_number: context.payload.issue.number,
body: `Hi @${creator}, Thank you for filing the issue! We will take a look and get back to you.`
});