Fix CI checkout after github new security policy
Github now fails with the following error when using `on: pull_request_target`: ``` Error: Refusing to check out fork pull request code from a 'pull_request_target' workflow. This workflow runs with the base repository's GITHUB_TOKEN, secrets, default-branch cache scope, and runner access. Fetching and executing a fork's code in that trusted context commonly leads to "pwn request" vulnerabilities. To opt in, review the risks at https://gh.io/securely-using-pull_request_target and set 'allow-unsafe-pr-checkout: true' on the actions/checkout step. ``` This reverts https://github.com/nvim-lua/kickstart.nvim/pull/571 and reopens https://github.com/nvim-lua/kickstart.nvim/pull/570
This commit is contained in:
@@ -1,6 +1,10 @@
|
|||||||
# Check Lua Formatting
|
# Check Lua Formatting
|
||||||
name: Check Lua Formatting
|
name: Check Lua Formatting
|
||||||
on: pull_request_target
|
on:
|
||||||
|
push:
|
||||||
|
branches:
|
||||||
|
- master
|
||||||
|
pull_request:
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
stylua-check:
|
stylua-check:
|
||||||
@@ -10,8 +14,6 @@ jobs:
|
|||||||
steps:
|
steps:
|
||||||
- name: Checkout Code
|
- name: Checkout Code
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v6
|
||||||
with:
|
|
||||||
ref: ${{ github.event.pull_request.head.sha }}
|
|
||||||
- name: Stylua Check
|
- name: Stylua Check
|
||||||
uses: JohnnyMorganz/stylua-action@v4
|
uses: JohnnyMorganz/stylua-action@v4
|
||||||
with:
|
with:
|
||||||
|
|||||||
Reference in New Issue
Block a user