Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[guidelines] side-quest-17-07-repo-poisoning.md: incorrect network.allowed-domains field name

Closed Beginner friendly
#4,083 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
88/100
Issue type
Documentation
Clarity
Clearly specified
Activity status
Active
Domain
documentation

Research direction

Open workshop/side-quest-17-07-repo-poisoning.md and review the occurrences listed in the issue, comparing them with the network.allowed examples in the referenced workshop pages and gh-aw network documentation. Done means every prose reference and YAML key uses network.allowed/allowed consistently, with no allowed-domains occurrences remaining.

Written by the indexing model from the issue text.

Description

bug documentation guidelines

File reviewed

workshop/side-quest-17-07-repo-poisoning.md

Violations

Factual accuracy — wrong frontmatter field name

Offending text:

Apply the three gh-aw defences: contents: read, safe-outputs: create-pull-request, and network.allowed-domains.

The page also uses network.allowed-domains (and a network: / allowed-domains: YAML example) at lines 13, 111, 115-116, 166, 186, and 198.

Every other workshop page and workflow file in this repository (for example side-quest-10-02-jailbreak-brief.md, side-quest-16-03-token-exfiltration.md, side-quest-16-05-long-lived-credentials.md, side-quest-17-02-security-architecture.md, side-quest-24-01-runner-infrastructure.md, side-quest-25-01-audit-reference.md, and all .github/workflows/*.md files) uses network.allowed. The upstream github/gh-aw docs (docs/src/content/docs/reference/network.md) also confirm the field is network: / allowed:, not allowed-domains:.

Suggested fix:
Replace every network.allowed-domains reference and the allowed-domains: YAML key in this file with network.allowed / allowed:, matching the usage in every other workshop page (e.g., side-quest-25-01-audit-reference.md). This requires editing several spots (prose mentions, a YAML code block, a table row, and a checklist item), so it needs a careful full-file pass rather than a single mechanical substitution.

Checklist size limit exceeded (related complex violation also tracked for this file's sibling; noting here since it touches the same hardening section)

No separate action needed here — see the companion issue for side-quest-21-01-sub-agent-syntax.md checkbox count.

[!WARNING]

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • registry.npmjs.org

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "registry.npmjs.org"

See Network Configuration for more information.

Generated by 📋 Guidelines Enforcer · copilot · auto · 143.1 AIC · ⌖ 6.13 AIC · ⊞ 9.6K · ◷

  • expires on Oct 9, 2026, 4:04 AM UTC
Dominant language
JavaScript
Stars
52
Forks
26
Avg merge
12h 25m
Merged PRs (30d)
18

Getting set up

Open in Codespaces

Starts the project's dev container in your browser, under your own GitHub account.

  • No Dockerfile or Docker Compose file
  • No pull request template
  • No contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from githubnext/gh-aw-workshop

All issues in githubnext/gh-aw-workshop

Similar issues

More JavaScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.