Repository navigation
security: gate chained E2E on same-repository checkout for workflow_run - #27780
DVHRMNTCBSL wants to merge 1 commit into
Conversation
|
Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA). View this failed invocation of the CLA check for more information. For the most up to date status, view the checks section at the bottom of the pull request. |
|
Note Gemini is unable to generate a summary for this pull request due to the file types involved not being currently supported. |
|
📊 PR Size: size/XS
|
|
Hi there! Thank you for your interest in contributing to Gemini CLI. To ensure we maintain high code quality and focus on our prioritized roadmap, we only guarantee review and consideration of pull requests for issues that are explicitly labeled as 'help wanted'. This PR will be closed in 7 days if it remains without that designation. We encourage you to find and contribute to existing 'help wanted' issues in our backlog! Thank you for your understanding. |
|
Closing this pull request as it does not have an associated tracked issue linked, and there has been no progress since the nudge. |
Fork PR
workflow_runchains can supply attacker-controlledrepository+shavia artifact metadata whileGEMINI_API_KEYis mounted inchained_e2e.ymljobs.This PR skips Linux/macOS/Windows/evals jobs that checkout
parse_run_context.outputs.repositorywhen that repository is notgithub.repository.Before: External fork can influence checkout ref/repo in jobs with
GEMINI_API_KEY.After: Only same-repo workflow_run / dispatch paths run secret-backed E2E.