[guidelines] side-quest-17-07-repo-poisoning.md: incorrect network.allowed-domains field name
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 88/100
- Issue type
- Documentation
- Clarity
- Clearly specified
- Activity status
- Active
- Domain
- documentation
Research direction
Open workshop/side-quest-17-07-repo-poisoning.md and review the occurrences listed in the issue, comparing them with the network.allowed examples in the referenced workshop pages and gh-aw network documentation. Done means every prose reference and YAML key uses network.allowed/allowed consistently, with no allowed-domains occurrences remaining.
Written by the indexing model from the issue text.
Description
File reviewed
workshop/side-quest-17-07-repo-poisoning.md
Violations
Factual accuracy — wrong frontmatter field name
Offending text:
Apply the three gh-aw defences:
contents: read,safe-outputs: create-pull-request, andnetwork.allowed-domains.
The page also uses network.allowed-domains (and a network: / allowed-domains: YAML example) at lines 13, 111, 115-116, 166, 186, and 198.
Every other workshop page and workflow file in this repository (for example side-quest-10-02-jailbreak-brief.md, side-quest-16-03-token-exfiltration.md, side-quest-16-05-long-lived-credentials.md, side-quest-17-02-security-architecture.md, side-quest-24-01-runner-infrastructure.md, side-quest-25-01-audit-reference.md, and all .github/workflows/*.md files) uses network.allowed. The upstream github/gh-aw docs (docs/src/content/docs/reference/network.md) also confirm the field is network: / allowed:, not allowed-domains:.
Suggested fix:
Replace every network.allowed-domains reference and the allowed-domains: YAML key in this file with network.allowed / allowed:, matching the usage in every other workshop page (e.g., side-quest-25-01-audit-reference.md). This requires editing several spots (prose mentions, a YAML code block, a table row, and a checklist item), so it needs a careful full-file pass rather than a single mechanical substitution.
Checklist size limit exceeded (related complex violation also tracked for this file's sibling; noting here since it touches the same hardening section)
No separate action needed here — see the companion issue for side-quest-21-01-sub-agent-syntax.md checkbox count.
[!WARNING]
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
registry.npmjs.orgTo allow these domains, add them to the
network.allowedlist in your workflow frontmatter:network: allowed: - defaults - "registry.npmjs.org"See Network Configuration for more information.
Generated by 📋 Guidelines Enforcer · copilot · auto · 143.1 AIC · ⌖ 6.13 AIC · ⊞ 9.6K · ◷
- expires on Oct 9, 2026, 4:04 AM UTC
- Dominant language
- JavaScript
- Stars
- 52
- Forks
- 26
- Avg merge
- 12h 25m
- Merged PRs (30d)
- 18
Getting set up
Starts the project's dev container in your browser, under your own GitHub account.
- No Dockerfile or Docker Compose file
- No pull request template
- No contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from githubnext/gh-aw-workshop
-
feedback simulation workshop
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
githubnext/gh-aw-workshop#4417 ·
Maintainers usually reply within 1 day
-
feedback simulation workshop
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
githubnext/gh-aw-workshop#4416 ·
Maintainers usually reply within 1 day
-
documentation
Difficulty 1/5 Under an hour Newbie friendliness 78/100
githubnext/gh-aw-workshop#4413 ·
Maintainers usually reply within 1 day
-
documentation
Difficulty 1/5 Under an hour Newbie friendliness 88/100
githubnext/gh-aw-workshop#4410 ·
Maintainers usually reply within 1 day
-
documentation
Difficulty 1/5 Under an hour Newbie friendliness 88/100
githubnext/gh-aw-workshop#4411 ·
Maintainers usually reply within 1 day
All issues in githubnext/gh-aw-workshop
Similar issues
-
bug user-priority/P2
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
Maintainers usually reply within 1 day
-
bug confirmed perf
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
videojs/video.js#9400 · 1 comment ·
Maintainers usually reply within 1 day
-
agent/scanner bug hive/hosted-available-lke648397-260827-5n31
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
rescript-lang/rescript#8765 ·
Maintainers usually reply within 1 day
-
[Good First Issue]: Add unit tests for NetworkVersionInfoPossibly taken @attilayener claimed this today. OpenGood First Issue hacktoberfest
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
hiero-ledger/hiero-sdk-js#4489 ·
Maintainers usually reply within 1 day