Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -3,13 +3,15 @@ rules:
languages:
- yaml
severity: ERROR
message: pull_request_target is considered very risky and should only be used when strictly needed. Please prefer other triggers when possible. If you think this is needed, you can dismiss this alert and merge your PR.
message: 'pull_request_target is considered very risky and should only be used when strictly needed. Please
prefer other triggers when possible. If you think this is needed, you can dismiss this alert and
merge your PR. More information: https://google.github.io/github-team/semgrep-rules/pull-request-target-needs-exception.html'
Comment thread
billnapier marked this conversation as resolved.
metadata:
category: best-practice
technology:
- github-actions
- github-actions
patterns:
- pattern-either:
- patterns:
- pattern-inside: "{on: ...}"
- pattern: pull_request_target
- pattern: pull_request_target