mirror of
https://github.com/NixOS/nixpkgs.git
synced 2026-10-02 21:10:08 +00:00
workflows/eval: allow fork PR checkout of ci/pinned.json
actions/checkout v7 refuses to check out fork PR commits from
pull_request_target workflows unless allow-unsafe-pr-checkout is set.
The versions job checks out ci/pinned.json at the PR's merge commit,
which matches pull_request.merge_commit_sha (or head.sha) in the event
payload and would be rejected.
Only ci/pinned.json is checked out, without persisted credentials, and
it is read as data by trusted/ci/supportedVersions.nix, so opting in is
safe.
Assisted-by: Claude Code (claude-opus-5-5)
(cherry picked from commit 9d1a3338ee)
This commit is contained in:
committed by
github-actions[bot]
parent
4945a1321e
commit
da8d99bb46
3
.github/workflows/eval.yml
vendored
3
.github/workflows/eval.yml
vendored
@@ -65,6 +65,9 @@ jobs:
|
||||
path: untrusted
|
||||
sparse-checkout: |
|
||||
ci/pinned.json
|
||||
# ci/pinned.json is only read as data by trusted/ci/supportedVersions.nix,
|
||||
# so checking out the fork PR's merge commit is safe here.
|
||||
allow-unsafe-pr-checkout: true
|
||||
|
||||
- name: Find commit that touched ci/pinned.json
|
||||
id: find-pinned-commit
|
||||
|
||||
Reference in New Issue
Block a user