Fix CI checkout after github new security policy
Github now fails with the following error when using `on: pull_request_target`: ``` Error: Refusing to check out fork pull request code from a 'pull_request_target' workflow. This workflow runs with the base repository's GITHUB_TOKEN, secrets, default-branch cache scope, and runner access. Fetching and executing a fork's code in that trusted context commonly leads to "pwn request" vulnerabilities. To opt in, review the risks at https://gh.io/securely-using-pull_request_target and set 'allow-unsafe-pr-checkout: true' on the actions/checkout step. ``` This reverts https://github.com/nvim-lua/kickstart.nvim/pull/571 and reopens https://github.com/nvim-lua/kickstart.nvim/pull/570
This commit is contained in:
@@ -1,6 +1,10 @@
|
||||
# Check Lua Formatting
|
||||
name: Check Lua Formatting
|
||||
on: pull_request_target
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- master
|
||||
pull_request:
|
||||
|
||||
jobs:
|
||||
stylua-check:
|
||||
@@ -10,8 +14,6 @@ jobs:
|
||||
steps:
|
||||
- name: Checkout Code
|
||||
uses: actions/checkout@v6
|
||||
with:
|
||||
ref: ${{ github.event.pull_request.head.sha }}
|
||||
- name: Stylua Check
|
||||
uses: JohnnyMorganz/stylua-action@v4
|
||||
with:
|
||||
|
||||
Reference in New Issue
Block a user