docs(inputs.smart): Document sudo-rs incompatibility #3912
milestones.yml
on: pull_request_target
Assign milestones to PRs
4s
Annotations
1 error
|
Assign milestones to PRs
Refusing to check out fork pull request code from a 'pull_request_target' workflow. This workflow runs with the base repository's GITHUB_TOKEN, secrets, default-branch cache scope, and runner access. Fetching and executing a fork's code in that trusted context commonly leads to "pwn request" vulnerabilities. To opt in, review the risks at https://gh.io/securely-using-pull_request_target and set 'allow-unsafe-pr-checkout: true' on the actions/checkout step.
|