From nobody Mon Apr 28 21:36:37 2025 X-Original-To: dev-commits-src-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4ZmcGG5s4Fz5tw0n; Mon, 28 Apr 2025 21:36:38 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R11" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4ZmcGF2w9Mz3bkh; Mon, 28 Apr 2025 21:36:37 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1745876197; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=tTLbx9yXg+ix4dV+tci0ZTjkhw6oLcY8T0T6p97Py7k=; b=JnBRXcFGkEAIPv1ExGizZA1jMeH//x/UtDvomQD9BD0xN7TksIgtcWuucRC5PPnwB9er3b OXlIXD6SfVfA6pUv4YaI6BtThgAvQVKX0AZEX/rbskxo8jFCCpVVEJVsw5m9FJplQXvfNU uvkT+OyiFV/L6mHomRTQ2s1n1FdosIymRPe4Ah49MGrl4PXzmgjwE61hBoTTeosr1ZcjI/ sEipCU0T0mjLW8mTR/q8o910212Gvx3vNTiYfFhCCFj6SNrh4OATE14up1fDt7b0pB+tAh eeV3TKq8VCsgiSv3dAtML7GX/U1c7WUC4zbgHnfUQeV2ZpGkiW7XMdYl5bvX2Q== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1745876197; a=rsa-sha256; cv=none; b=A7jfGk9J1M0SuFjjWHDlZ392BPEvwqkLNfj9BnZGG1yreLWVG8Tj0CgKVkwivgbEpYH+Mc YBZR9E+7rR5obvZKfsI+aJuAOa4ZSiArfm4MYFr7+01pn88bryB1f9OUddQ5g+c3VsrTzh ZmaOPm+tuSBLy/rGN6qw13+yIkuGlX0d8zM2ptan+s9MUFT0EVChdoDyjllddA+Zt3oOU7 WABrpvJL43agE7w7deO+0FIScHMOakZBGZDc5eyDOYFbGZPk6oNumYJLH4IFS2tsJhgR7i Mac5zXnLPurO60nN3kYdHApv3XY9cRulPuNl4mXrdhsDssUKFWRQPkWwfAqCHg== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1745876197; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=tTLbx9yXg+ix4dV+tci0ZTjkhw6oLcY8T0T6p97Py7k=; b=YZ1y7sn9UzK7ckbVLEn/wJyMA4LU+e32mc0s8KgwTbxKwDg57A25xod6fbBKNl1n+AmUXA bTzgBYNB6wqm8VTUWTs7u2DvshBCN3OiCs4Js6HqnGwgMqhG/tLsvmZHmZ6AUpJ+qD1ksA jtkkTOqvnok8TGjnq2TViR/OWRLOE2pDRO6JaNgNdVk47TA7x/48pcqZDR2F6ewnvok3Qp 5Q27les7M0kVO+c6y6TbjUhYEArpyc1Z8M3Lnx1JXnwGe7cePceDeJJ+7BHTMBFq7BLljM cxIW+tI9W/ZWYQu2J450Gcbzf9wSL8O9hnxVxFwNBPahGCbdFJ94OGPW8xS/+w== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4ZmcGF2D2tzsBK; Mon, 28 Apr 2025 21:36:37 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.18.1/8.18.1) with ESMTP id 53SLabeA057670; Mon, 28 Apr 2025 21:36:37 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.18.1/8.18.1/Submit) id 53SLabID057667; Mon, 28 Apr 2025 21:36:37 GMT (envelope-from git) Date: Mon, 28 Apr 2025 21:36:37 GMT Message-Id: <202504282136.53SLabID057667@gitrepo.freebsd.org> To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Warner Losh Subject: git: 8528d7e4f642 - main - github: Fix checklist action List-Id: Commit messages for the main branch of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-main@freebsd.org Sender: owner-dev-commits-src-main@FreeBSD.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: imp X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 8528d7e4f64206ab6288182aa65c0c159a746828 Auto-Submitted: auto-generated The branch main has been updated by imp: URL: https://cgit.FreeBSD.org/src/commit/?id=8528d7e4f64206ab6288182aa65c0c159a746828 commit 8528d7e4f64206ab6288182aa65c0c159a746828 Author: Ahmad Khalifa AuthorDate: 2025-01-25 16:59:19 +0000 Commit: Warner Losh CommitDate: 2025-04-28 21:27:29 +0000 github: Fix checklist action Workflows triggered by the 'pull_request' event can't have write permissions. With write permissions a malicious pull request can alter or create a workflow that either leaks the GITHUB_TOKEN with the write permissions or do malicious things in the workflow itself. The 'pull_request_target' event on the other hand allows workflows to run with write permissions but runs on the merge base of the PR, this way a pull request that alters such a workflow will not have it's code run until it's merged. Signed-off-by: Ahmad Khalifa Reviewed by: imp, emaste Pull Request: https://github.com/freebsd/freebsd-src/pull/1581 --- .github/workflows/checklist.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/checklist.yml b/.github/workflows/checklist.yml index 9734af4a1a1d..f5c3ea599abf 100644 --- a/.github/workflows/checklist.yml +++ b/.github/workflows/checklist.yml @@ -4,7 +4,7 @@ name: Checklist # for the submission to align with CONTRIBUTING.md on: - pull_request: + pull_request_target: types: [ opened, reopened, edited, synchronize ] permissions: