workflows/eval: allow fork PR checkout of ci/pinned.json

actions/checkout v7 refuses to check out fork PR commits from
pull_request_target workflows unless allow-unsafe-pr-checkout is set.
The versions job checks out ci/pinned.json at the PR's merge commit,
which matches pull_request.merge_commit_sha (or head.sha) in the event
payload and would be rejected.

Only ci/pinned.json is checked out, without persisted credentials, and
it is read as data by trusted/ci/supportedVersions.nix, so opting in is
safe.

Assisted-by: Claude Code (claude-opus-5-5)
(cherry picked from commit 9d1a3338ee)
This commit is contained in:
Philip Taron
2026-10-02 05:31:18 -07:00
committed by github-actions[bot]
parent 4945a1321e
commit da8d99bb46

View File

@@ -65,6 +65,9 @@ jobs:
path: untrusted
sparse-checkout: |
ci/pinned.json
# ci/pinned.json is only read as data by trusted/ci/supportedVersions.nix,
# so checking out the fork PR's merge commit is safe here.
allow-unsafe-pr-checkout: true
- name: Find commit that touched ci/pinned.json
id: find-pinned-commit