Harden Agentic CI PR reviews for forked pull requests
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 初心者へのやさしさ
- 35/100
調査の方向性
現在の pull_request_target workflow から始め、その checkout と認証情報の扱いを、PR #795 の互換性変更および #541 での元の移行と比較します。fork のパスと同一リポジトリのパスを追跡し、続いて issue に記載された workflow と制御された Fork-PR シナリオを検証します。完了の条件は、fork のコンテンツが決して実行も checkout もされず、認可が head SHA に紐付けられ、有用なレビュー結果が維持されることです。
索引モデルが issue の本文から書いたものです。
説明
Priority Level
High
Task Summary
Harden the Agentic CI PR review workflow so maintainer-approved fork PRs can be reviewed without exposing secrets, repository credentials, or the self-hosted runner to fork-controlled code and project configuration.
PR #795 upgrades actions/checkout to v7, which blocks fork PR checkout from pull_request_target workflows unless allow-unsafe-pr-checkout: true is set. As a short-term compatibility decision, #795 will explicitly opt in so behavior remains equivalent to the existing checkout v6 workflow. This issue tracks replacing that accepted risk with a hardened design.
Technical Details & Implementation Plan
Suggested approach:
- Resolve and validate immutable PR context before any checkout:
- PR number
- base SHA
- head SHA
- head repository
- whether the PR comes from a fork
- Keep the existing full Claude Code review path for same-repository PRs.
- For fork PRs, use a hardened diff-only path:
- Do not check out the fork.
- Do not run repository scripts, tests, hooks, project settings, or Claude Code tools.
- Fetch PR metadata, changed file names, and the diff through GitHub using the validated PR number and head SHA.
- Treat all PR metadata and diff content as untrusted data.
- Send only that inert review payload to the model through a tool-free API request.
- Set
persist-credentials: falseon checkouts and avoid making a write-capable repository token available to the model process. - Preserve explicit maintainer authorization for fork reviews and bind approval to the reviewed head SHA. A changed head must require fresh authorization.
- Minimize workflow permissions and isolate secret-bearing steps. Prefer an ephemeral runner for any job processing untrusted input.
- Audit or disable project-controlled Claude settings, hooks, and instruction files anywhere untrusted content can be present.
- Add workflow validation for:
- same-repository PRs
- maintainer-approved fork PRs
- fork head changes after approval
- manual
workflow_dispatchof a fork PR - missing model configuration and API failures
Acceptance criteria:
- Fork PR review does not check out or execute fork-controlled content.
- Fork-controlled project configuration cannot run on the self-hosted runner.
- Repository credentials are not persisted in the checkout.
- Authorization is tied to an immutable head SHA.
- Same-repository review behavior remains unchanged.
- The workflow still posts a useful advisory review or an explicit incomplete-review result.
Investigation / Context
The current workflow was intentionally moved to pull_request_target in #541 so approved fork PR reviews could access the model configuration and secrets. Existing safeguards include collaborator/label gating, an agentic-ci environment gate, and loading review recipes and tools from the base branch.
Those controls reduce exposure but do not fully isolate untrusted content:
- The fork working tree is placed on a self-hosted runner.
actions/checkoutpersists the repository token by default.- Claude Code runs with
GH_TOKENand model API credentials while inspecting untrusted content. - Prompt injection, project-controlled configuration, hooks, or tool execution could potentially read and exfiltrate credentials.
Checkout v7 made this trust boundary explicit by requiring allow-unsafe-pr-checkout: true for fork PR heads in pull_request_target and workflow_run workflows: https://github.com/actions/checkout/pull/2454
Related: #795 and #541.
Agent Plan / Findings
Implement the fork/non-fork split first. The preferred fork path is metadata-plus-diff review through a direct, tool-free model request. This retains useful automated review while removing the need to place fork code in the secret-bearing workspace.
After implementation, validate workflow syntax locally and perform a controlled fork PR smoke test. Confirm that the reviewed SHA appears in workflow logs and that updating the fork requires new authorization.
Dependencies
Short-term compatibility opt-in in PR #795.
- 主要言語
- Python
- スター
- 2.3k
- フォーク
- 211
- 平均マージ
- 3日 12時間
- マージ済み PR(30日)
- 45
環境構築
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
NVIDIA-NeMo/DataDesigner のほかの issue
-
task
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
NVIDIA-NeMo/DataDesigner#760 ·
メンテナーはふだん 1 日以内に返信
-
Harden Slurm inference routing, backpressure, and failover対応中かも @nabinchha が 1 日前に担当しました。 オープンtask
NVIDIA-NeMo/DataDesigner#966 · 担当者 1 名 ·
メンテナーはふだん 1 日以内に返信
-
enhancement triaged
難易度 4/5 3〜5日 初心者へのやさしさ 40/100
NVIDIA-NeMo/DataDesigner#956 ·
メンテナーはふだん 1 日以内に返信
-
task
難易度 5/5 1週間以上 初心者へのやさしさ 42/100
NVIDIA-NeMo/DataDesigner#947 ·
メンテナーはふだん 1 日以内に返信
-
bug
難易度 4/5 3〜5日 初心者へのやさしさ 52/100
NVIDIA-NeMo/DataDesigner#946 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
NVIDIA-NeMo/DataDesigner の issue をすべて見る
似ている issue
-
難易度 1/5 1時間未満 初心者へのやさしさ 72/100
letsencrypt/cp-cps#353 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
PedestrianDynamics/pyFDS-Evac#394 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
DOI-USGS/pywatershed#421 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
python-pillow/Pillow#10087 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信