Test CI is failing for external contributors
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 35/100
Línea de trabajo
Start by reading the existing test CI workflow and the linked GitHub Security Lab article, then inspect how external pull requests handle secrets and the coverage.xml artifact. Confirm the two-workflow approach in a test external-contributor scenario. Done means test CI remains safe and coverage.xml is published successfully for external contributors.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Currently, test CI is using the pull_request trigger. However, with this trigger the secrets are not populated when the PR author is external to the repository.
This is done on purpose for security reasons: https://securitylab.github.com/resources/github-actions-preventing-pwn-requests/
Many persons on the internet suggest to use pull_request_target, but according to a rapid oversight of github securitylab article, this is only a workaround with does not help with security at all.
The proper solution seems to separate the workflow in two:
- existing workflow will only publish the coverage.xml as an artifact
- a new workflow will be responsible to publish this coverage.xml
Seems pretty simple to implement, but to be confirmed (I skimmed through github article way too fast) and tested of course.
- Lenguaje dominante
- Python
- Estrellas
- 1
- Forks
- 2
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Guía de contribución
No hay ninguna guía de contribución indexada para este repositorio
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de openzim/_python-bootstrap
-
bug
Dificultad 1/5 Menos de una hora Aptitud para principiantes 76/100
openzim/_python-bootstrap#57 ·
-
enhancement
openzim/_python-bootstrap#54 · 1 comentario · 2 asignados ·
-
Workflow convention Abiertoquestion
openzim/_python-bootstrap#53 · 1 asignado ·
-
Move `.pre-commit.yaml` to hatch Abiertoenhancement
Dificultad 3/5 1-2 días Aptitud para principiantes 25/100
openzim/_python-bootstrap#51 · 3 comentarios ·
-
What about nested logs Abiertoenhancement
openzim/_python-bootstrap#48 · 2 asignados ·
Todos los issues de openzim/_python-bootstrap
Issues similares
-
bug confirmed issue
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
open-webui/open-webui#30750 · 1 comentario ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
-
enhancement
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
OpenwaterHealth/openmotion-bloodflow-app#604 · 1 comentario ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
-
good first issue
Dificultad 1/5 Menos de una hora Aptitud para principiantes 90/100