Protect against malicious branch names
This commit is contained in:
parent
fe81ac334c
commit
d598623305
1 changed files with 2 additions and 2 deletions
4
.github/workflows/danger.yml
vendored
4
.github/workflows/danger.yml
vendored
|
@ -24,10 +24,10 @@ jobs:
|
|||
bundler-cache: true
|
||||
- name: Create base branch
|
||||
run: |
|
||||
git fetch ${{ github.event.pull_request.base.repo.clone_url }} ${{ github.event.pull_request.base.ref }}:danger_base
|
||||
git fetch ${{ github.event.pull_request.base.repo.clone_url }} ${{ github.event.pull_request.base.sha }}:danger_base
|
||||
- name: Create head branch
|
||||
run: |
|
||||
git fetch ${{ github.event.pull_request.head.repo.clone_url }} ${{ github.event.pull_request.head.ref }}:danger_head
|
||||
git fetch ${{ github.event.pull_request.head.repo.clone_url }} ${{ github.event.pull_request.head.sha }}:danger_head
|
||||
- name: Danger
|
||||
env:
|
||||
DANGER_GITHUB_BEARER_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue