summaryrefslogtreecommitdiff
path: root/.github
diff options
context:
space:
mode:
authorDonatas Abraitis <donatas@opensourcerouting.org>2022-05-25 19:07:40 +0300
committerDonatas Abraitis <donatas@opensourcerouting.org>2022-05-25 19:07:40 +0300
commit4588d0cb4955e47a7ad3c38963a018a0284ac990 (patch)
tree21611cbf7c02c1d741a34d748e02e71e6da1b4f6 /.github
parentad5124419f9d7723cc91548e63fbfb4f844e20ce (diff)
github: Use pull_request_target as a target
And drop checkout action - not needed. Due to the dangers inherent to automatic processing of PRs, GitHub’s standard pull_request workflow trigger by default prevents write permissions and secrets access to the target repository. However, in some scenarios such access is needed to properly process the PR. To this end the pull_request_target workflow trigger was introduced. Signed-off-by: Donatas Abraitis <donatas@opensourcerouting.org>
Diffstat (limited to '.github')
-rw-r--r--.github/workflows/base-branch-label.yml3
1 files changed, 1 insertions, 2 deletions
diff --git a/.github/workflows/base-branch-label.yml b/.github/workflows/base-branch-label.yml
index 9572ee7ee2..01da280911 100644
--- a/.github/workflows/base-branch-label.yml
+++ b/.github/workflows/base-branch-label.yml
@@ -1,7 +1,7 @@
name: Add base branch label
on:
- pull_request:
+ pull_request_target:
types:
- opened
- reopened
@@ -13,7 +13,6 @@ jobs:
contents: read
pull-requests: write
steps:
- - uses: actions/checkout@v2
- uses: actions-ecosystem/action-add-labels@v1
with:
labels: |